2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2806 | MEDIUM | 6.1 | 0.3% | May 8, 2025 | The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting v... |
| CVE-2025-41450 | HIGH | 8.2 | 0.3% | May 8, 2025 | Improper Authentication vulnerability in Danfoss AKSM8xxA Series.This issue affects Danfoss AK-SM 8xxA Series prior to v... |
| CVE-2025-3759 | HIGH | 8.7 | 0.2% | May 8, 2025 | Endpoint /cgi-bin-igd/netcore_set.cgi which is used for changing device configuration is accessible without authenticati... |
| CVE-2025-3758 | HIGH | 8.7 | 0.2% | May 8, 2025 | WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to unauthorized users. Ret... |
| CVE-2025-40846 | HIGH | 7.1 | 0.3% | May 8, 2025 | Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing ... |
| CVE-2025-1254 | HIGH | 7.4 | 0.2% | May 8, 2025 | Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Bu... |
| CVE-2025-1253 | HIGH | 7.8 | 0.1% | May 8, 2025 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI... |
| CVE-2025-1252 | HIGH | 7.1 | 0.1% | May 8, 2025 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags... |
| CVE-2025-4127 | MEDIUM | 5.4 | 0.2% | May 8, 2025 | The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range... |
| CVE-2025-37834 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: don't try to reclaim hwpoison folio Syz... |
| CVE-2025-37833 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/niu: Niu requires MSIX ENTRY_DATA fields touch ... |
| CVE-2025-37832 | — | — | — | May 8, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-37831 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix null-ptr-deref in apple_soc... |
| CVE-2025-37830 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_g... |
| CVE-2025-37829 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_g... |
| CVE-2025-37828 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort(... |
| CVE-2025-37827 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: return EIO on RAID1 block group write... |
| CVE-2025-37826 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Add NULL check in ufshcd_mcq_compl... |
| CVE-2025-37825 | HIGH | 7.1 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix out-of-bounds access in nvmet_enable_por... |
| CVE-2025-37824 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL pointer dereference in tipc_mon_rein... |
| CVE-2025-37823 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a potential UAF in hfsc_dequeu... |
| CVE-2025-37822 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: riscv: uprobes: Add missing fence.i after building ... |
| CVE-2025-37821 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched/eevdf: Fix se->slice being set to U64_MAX and... |
| CVE-2025-37820 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: xen-netfront: handle NULL returned by xdp_convert_b... |
| CVE-2025-37819 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v2m: Prevent use after free of gicv2m_g... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now