2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70986HIGH7.5Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access ...
CVE-2025-70985CRITICAL9.1Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data...
CVE-2025-70983CRITICAL9.9Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to ...
CVE-2025-14947MEDIUM6.5The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-71177MEDIUM5.4LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package crea...
CVE-2025-67231MEDIUM5.9A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary ...
CVE-2025-67230HIGH7.1Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with rendere...
CVE-2025-67229CRITICAL9.8An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauth...
CVE-2025-71161MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correcti...
CVE-2025-71160MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: avoid chain re-validation if ...
CVE-2025-71159HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free warning in btrfs_get_or_c...
CVE-2025-71158MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IR...
CVE-2025-69908HIGH7.5An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged...
CVE-2025-67125MEDIUM4.4A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern::match in docopt_private.h) when merging occurrence counters...
CVE-2025-67124MEDIUM6.8A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an atta...
CVE-2025-66720HIGH7.5Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePolicie...
CVE-2025-66719CRITICAL9.1An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck...
CVE-2025-71157HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/core: always drop device refcount in ib_del_su...
CVE-2025-71156HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registrati...
CVE-2025-71155HIGH7.8In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix gmap_helper_zap_one_page() again A ...
CVE-2025-71154MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix memory leak on usb_submit_ur...
CVE-2025-71153MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix memory leak in get_file_all_info() In g...
CVE-2025-71152HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: dsa: properly keep track of conduit reference ...
CVE-2025-71151MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3_recon...
CVE-2025-71150MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix refcount leak when invalid session is fo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now