2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2806MEDIUM6.1The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting v...
CVE-2025-41450HIGH8.2Improper Authentication vulnerability in Danfoss AKSM8xxA Series.This issue affects Danfoss AK-SM 8xxA Series prior to v...
CVE-2025-3759HIGH8.7Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authenticati...
CVE-2025-3758HIGH8.7WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Ret...
CVE-2025-40846HIGH7.1Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing ...
CVE-2025-1254HIGH7.4Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Bu...
CVE-2025-1253HIGH7.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI...
CVE-2025-1252HIGH7.1Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags...
CVE-2025-4127MEDIUM5.4The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range...
CVE-2025-37834MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: don't try to reclaim hwpoison folio Syz...
CVE-2025-37833MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/niu: Niu requires MSIX ENTRY_DATA fields touch ...
CVE-2025-37832Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-37831MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix null-ptr-deref in apple_soc...
CVE-2025-37830MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_g...
CVE-2025-37829MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_g...
CVE-2025-37828MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort(...
CVE-2025-37827MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: return EIO on RAID1 block group write...
CVE-2025-37826MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Add NULL check in ufshcd_mcq_compl...
CVE-2025-37825HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nvmet: fix out-of-bounds access in nvmet_enable_por...
CVE-2025-37824MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL pointer dereference in tipc_mon_rein...
CVE-2025-37823HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a potential UAF in hfsc_dequeu...
CVE-2025-37822HIGH7.8In the Linux kernel, the following vulnerability has been resolved: riscv: uprobes: Add missing fence.i after building ...
CVE-2025-37821MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched/eevdf: Fix se->slice being set to U64_MAX and...
CVE-2025-37820MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xen-netfront: handle NULL returned by xdp_convert_b...
CVE-2025-37819HIGH7.8In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v2m: Prevent use after free of gicv2m_g...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now