2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39728 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init()... |
| CVE-2025-39688 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via n... |
| CVE-2025-38637 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue asse... |
| CVE-2025-38575 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_... |
| CVE-2025-38479 | HIGH | 7.8 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: free irq correctly in remove p... |
| CVE-2025-38240 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to... |
| CVE-2025-38152 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdow... |
| CVE-2025-38104 | MEDIUM | 4.7 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Replace Mutex with Spinlock for RLCG re... |
| CVE-2025-38049 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on p... |
| CVE-2025-37925 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type ... |
| CVE-2025-37893 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prolo... |
| CVE-2025-37860 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_... |
| CVE-2025-37785 | HIGH | 7.1 | 0.3% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounti... |
| CVE-2025-3783 | CRITICAL | 9.8 | 0.8% | Apr 18, 2025 | A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Aff... |
| CVE-2025-3598 | MEDIUM | 6.1 | 0.4% | Apr 18, 2025 | The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2025-2162 | MEDIUM | 4.8 | 0.3% | Apr 18, 2025 | The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could all... |
| CVE-2025-1863 | CRITICAL | 9.8 | 0.6% | Apr 18, 2025 | Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default se... |
| CVE-2025-39471 | CRITICAL | 9.3 | 0.3% | Apr 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal S... |
| CVE-2025-39470 | HIGH | 8.1 | 0.6% | Apr 18, 2025 | Path Traversal: '.../...//' vulnerability in ThimPress Ivy School ivy-school allows PHP Local File Inclusion.This issue ... |
| CVE-2025-39469 | HIGH | 7.1 | 0.2% | Apr 18, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pantherius Modal S... |
| CVE-2025-42599 | CRITICAL | 9.8 | 3.0% | Apr 18, 2025 | Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a sp... |
| CVE-2025-3520 | HIGH | 8.1 | 0.8% | Apr 18, 2025 | The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a f... |
| CVE-2025-2613 | MEDIUM | 4.4 | 0.2% | Apr 18, 2025 | The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to S... |
| CVE-2025-25427 | MEDIUM | 5.4 | 0.6% | Apr 18, 2025 | A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/... |
| CVE-2025-0467 | HIGH | 8.2 | 0.1% | Apr 18, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now