2025 CVE Vulnerabilities

45,280 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-37818MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: Return NULL from huge_pte_offset() for i...
CVE-2025-37817HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mcb: fix a double free bug in chameleon_parse_gdd()...
CVE-2025-37816MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mei: vsc: Fix fortify-panic caused by invalid count...
CVE-2025-37815MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: Fix Kernel panic during ...
CVE-2025-37814MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tty: Require CAP_SYS_ADMIN for all usages of TIOCL_...
CVE-2025-37813MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix invalid pointer dereference in Etron...
CVE-2025-37812MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: Fix deadlock when using NCM gadget The...
CVE-2025-37811MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: ci_hdrc_imx: fix usbmisc handling u...
CVE-2025-37810HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: check that event count does not ...
CVE-2025-37809MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Fix NULL pointer access Concurr...
CVE-2025-37808MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: null - Use spin lock instead of mutex As t...
CVE-2025-37807MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix kmemleak warning for percpu hashmap Vlad ...
CVE-2025-37806MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Keep write operations atomic syzbot repo...
CVE-2025-37805MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitial...
CVE-2025-37804Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-37803HIGH7.8In the Linux kernel, the following vulnerability has been resolved: udmabuf: fix a buf size overflow issue during udmab...
CVE-2025-37802MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !...
CVE-2025-37801MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Ad...
CVE-2025-37800MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference...
CVE-2025-3419HIGH7.5The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary fil...
CVE-2025-32873MEDIUM5.3An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip...
CVE-2025-46727HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses qu...
CVE-2025-35939MEDIUM5.3Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed an...
CVE-2025-32441MEDIUM4.2Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, s...
CVE-2025-0936MEDIUM6.5On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now