2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14187 | HIGH | 7.3 | 0.6% | Dec 7, 2025 | A weakness has been identified in UGREEN DH2100+ up to 5.3.0.251125. This affects the function handler_file_backup_creat... |
| CVE-2025-40285 | HIGH | 7.5 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess... |
| CVE-2025-40284 | HIGH | 7.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: cancel mesh send timer when hdev r... |
| CVE-2025-40283 | HIGH | 7.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: reorder cleanup in btusb_disconne... |
| CVE-2025-40282 | HIGH | 8.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: reset link-local header on ipv6... |
| CVE-2025-40280 | HIGH | 7.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self().... |
| CVE-2025-40277 | HIGH | 7.8 | 0.3% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SV... |
| CVE-2025-40276 | HIGH | 7.3 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Flush shmem writes before mapping buff... |
| CVE-2025-40274 | HIGH | 7.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: guest_memfd: Remove bindings on memslot deleti... |
| CVE-2025-40273 | HIGH | 8.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: NFSD: free copynotify stateid in nfs4_free_ol_state... |
| CVE-2025-40272 | HIGH | 7.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/secretmem: fix use-after-free race in fault hand... |
| CVE-2025-40271 | HIGH | 7.8 | 0.5% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erase... |
| CVE-2025-40270 | HIGH | 7.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm, swap: fix potential UAF issue for VMA readahead... |
| CVE-2025-40269 | HIGH | 7.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential overflow of PCM tran... |
| CVE-2025-14136 | HIGH | 8.8 | 1.0% | Dec 6, 2025 | A security flaw has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/... |
| CVE-2025-14135 | HIGH | 8.8 | 0.7% | Dec 6, 2025 | A vulnerability was identified in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0... |
| CVE-2025-14134 | HIGH | 8.8 | 0.7% | Dec 6, 2025 | A vulnerability was determined in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0... |
| CVE-2025-14133 | HIGH | 8.8 | 0.7% | Dec 6, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
| CVE-2025-14126 | HIGH | 8.8 | 0.4% | Dec 6, 2025 | A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the c... |
| CVE-2025-13065 | HIGH | 8.8 | 7.1% | Dec 6, 2025 | The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, ... |
| CVE-2025-12966 | HIGH | 8.8 | 0.4% | Dec 6, 2025 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2025-12499 | HIGH | 7.2 | 0.3% | Dec 6, 2025 | The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the content... |
| CVE-2025-13377 | HIGH | 8.1 | 0.5% | Dec 6, 2025 | The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbit... |
| CVE-2025-13292 | HIGH | 7.6 | 0.2% | Dec 6, 2025 | A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data... |
| CVE-2025-12510 | HIGH | 7.2 | 0.4% | Dec 6, 2025 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now