2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54160 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology Bee... |
| CVE-2025-54159 | HIGH | 7.5 | 0.4% | Dec 4, 2025 | Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attack... |
| CVE-2025-54158 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-139... |
| CVE-2025-40266 | HIGH | 8.2 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memo... |
| CVE-2025-40262 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload... |
| CVE-2025-40253 | HIGH | 8.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: s390/ctcm: Fix double-kfree The function 'mpc_rcvd... |
| CVE-2025-40250 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq... |
| CVE-2025-40249 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: make sure the cdev fd is still active b... |
| CVE-2025-40248 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if alread... |
| CVE-2025-40245 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: nios2: ensure that memblock.current_limit is set wh... |
| CVE-2025-40244 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in __hfsplus_... |
| CVE-2025-40243 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: hfs: fix KMSAN uninit-value issue in hfs_find_set_z... |
| CVE-2025-40242 | HIGH | 7 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_p... |
| CVE-2025-40241 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix crafted invalid cases for encoded extent... |
| CVE-2025-40240 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: sctp: avoid NULL dereference when chunk data buffer... |
| CVE-2025-40233 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: clear extent cache after moving/defragmentin... |
| CVE-2025-54307 | HIGH | 8.8 | 0.6% | Dec 4, 2025 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/uplo... |
| CVE-2025-54306 | HIGH | 7.2 | 0.7% | Dec 4, 2025 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerabil... |
| CVE-2025-54305 | HIGH | 7.8 | 0.1% | Dec 4, 2025 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in... |
| CVE-2025-40216 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment ... |
| CVE-2025-29846 | HIGH | 7.2 | 0.6% | Dec 4, 2025 | A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages. |
| CVE-2025-14008 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec22... |
| CVE-2025-40215 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: xfrm: delete x->tunnel as we delete x The ipcomp f... |
| CVE-2025-40214 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). ... |
| CVE-2025-11727 | HIGH | 7.2 | 0.2% | Dec 4, 2025 | The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now