2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14012 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of... |
| CVE-2025-14011 | HIGH | 7.2 | 0.3% | Dec 4, 2025 | A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Co... |
| CVE-2025-66287 | HIGH | 8.8 | 0.5% | Dec 4, 2025 | A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper me... |
| CVE-2025-63364 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00... |
| CVE-2025-57213 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensiti... |
| CVE-2025-57212 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive i... |
| CVE-2025-57210 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive ... |
| CVE-2025-56427 | HIGH | 7.5 | 0.8% | Dec 4, 2025 | Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via th... |
| CVE-2025-54160 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology Bee... |
| CVE-2025-54159 | HIGH | 7.5 | 0.4% | Dec 4, 2025 | Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attack... |
| CVE-2025-54158 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-139... |
| CVE-2025-40266 | HIGH | 8.2 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memo... |
| CVE-2025-40262 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload... |
| CVE-2025-40253 | HIGH | 8.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: s390/ctcm: Fix double-kfree The function 'mpc_rcvd... |
| CVE-2025-40250 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq... |
| CVE-2025-40249 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: make sure the cdev fd is still active b... |
| CVE-2025-40248 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if alread... |
| CVE-2025-40245 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: nios2: ensure that memblock.current_limit is set wh... |
| CVE-2025-40244 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in __hfsplus_... |
| CVE-2025-40243 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: hfs: fix KMSAN uninit-value issue in hfs_find_set_z... |
| CVE-2025-40242 | HIGH | 7 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_p... |
| CVE-2025-40241 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix crafted invalid cases for encoded extent... |
| CVE-2025-40240 | HIGH | 7.5 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: sctp: avoid NULL dereference when chunk data buffer... |
| CVE-2025-40233 | HIGH | 7.8 | 0.2% | Dec 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: clear extent cache after moving/defragmentin... |
| CVE-2025-54307 | HIGH | 8.8 | 0.6% | Dec 4, 2025 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/uplo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now