2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71149Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71148LOW3.3In the Linux kernel, the following vulnerability has been resolved: net/handshake: restore destructor on submit failure...
CVE-2025-71147MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd ...
CVE-2025-71146MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error pat...
CVE-2025-69907HIGH7.5An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and acce...
CVE-2025-71145HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: phy: isp1301: fix non-OF device reference imba...
CVE-2025-13921MEDIUM4.3The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unau...
CVE-2025-4320CRITICAL10Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Bire...
CVE-2025-4319CRITICAL9.4Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne...
CVE-2025-14866HIGH8.8The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin...
CVE-2025-2204MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tapandsign ...
CVE-2025-46699MEDIUM6.5Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a...
CVE-2025-14745MEDIUM6.4The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored...
CVE-2025-14069MEDIUM6.4The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sas...
CVE-2025-67847HIGH8.8A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbi...
CVE-2025-3839HIGH8A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user in...
CVE-2025-15522MEDIUM6.4The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2025-15351HIGH7.8Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab...
CVE-2025-15350HIGH7.8Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab...
CVE-2025-15349HIGH7.5Anritsu ShockLine SCPI Race Condition Remote Code Execution Vulnerability. This vulnerability allows network-adjacent at...
CVE-2025-15348HIGH7.8Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi...
CVE-2025-15063CRITICAL9.8Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote atta...
CVE-2025-15062HIGH7.8Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2025-15061CRITICAL9.8Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2025-15059HIGH7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now