2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-39728MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init()...
CVE-2025-39688MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via n...
CVE-2025-38637MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue asse...
CVE-2025-38575MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_...
CVE-2025-38479HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: free irq correctly in remove p...
CVE-2025-38240MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to...
CVE-2025-38152MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdow...
CVE-2025-38104MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Replace Mutex with Spinlock for RLCG re...
CVE-2025-38049MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on p...
CVE-2025-37925MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type ...
CVE-2025-37893MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prolo...
CVE-2025-37860MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_...
CVE-2025-37785HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounti...
CVE-2025-3783CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Aff...
CVE-2025-3598MEDIUM6.1The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri...
CVE-2025-2162MEDIUM4.8The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could all...
CVE-2025-1863CRITICAL9.8Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default se...
CVE-2025-39471CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal S...
CVE-2025-39470HIGH8.1Path Traversal: '.../...//' vulnerability in ThimPress Ivy School ivy-school allows PHP Local File Inclusion.This issue ...
CVE-2025-39469HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pantherius Modal S...
CVE-2025-42599CRITICAL9.8Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a sp...
CVE-2025-3520HIGH8.1The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a f...
CVE-2025-2613MEDIUM4.4The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to S...
CVE-2025-25427MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/...
CVE-2025-0467HIGH8.2Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now