2025 CVE Vulnerabilities
45,280 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-37818 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Return NULL from huge_pte_offset() for i... |
| CVE-2025-37817 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: mcb: fix a double free bug in chameleon_parse_gdd()... |
| CVE-2025-37816 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: mei: vsc: Fix fortify-panic caused by invalid count... |
| CVE-2025-37815 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: Fix Kernel panic during ... |
| CVE-2025-37814 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: tty: Require CAP_SYS_ADMIN for all usages of TIOCL_... |
| CVE-2025-37813 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix invalid pointer dereference in Etron... |
| CVE-2025-37812 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: Fix deadlock when using NCM gadget The... |
| CVE-2025-37811 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: chipidea: ci_hdrc_imx: fix usbmisc handling u... |
| CVE-2025-37810 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: check that event count does not ... |
| CVE-2025-37809 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Fix NULL pointer access Concurr... |
| CVE-2025-37808 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: null - Use spin lock instead of mutex As t... |
| CVE-2025-37807 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix kmemleak warning for percpu hashmap Vlad ... |
| CVE-2025-37806 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Keep write operations atomic syzbot repo... |
| CVE-2025-37805 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitial... |
| CVE-2025-37804 | — | — | — | May 8, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-37803 | HIGH | 7.8 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: udmabuf: fix a buf size overflow issue during udmab... |
| CVE-2025-37802 | MEDIUM | 5.5 | 0.3% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !... |
| CVE-2025-37801 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Ad... |
| CVE-2025-37800 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference... |
| CVE-2025-3419 | HIGH | 7.5 | 0.6% | May 8, 2025 | The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary fil... |
| CVE-2025-32873 | MEDIUM | 5.3 | 14.0% | May 8, 2025 | An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip... |
| CVE-2025-46727 | HIGH | 7.5 | 0.9% | May 7, 2025 | Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses qu... |
| CVE-2025-35939 | MEDIUM | 5.3 | 1.1% | May 7, 2025 | Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed an... |
| CVE-2025-32441 | MEDIUM | 4.2 | 0.2% | May 7, 2025 | Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, s... |
| CVE-2025-0936 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now