2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52024CRITICAL9.4A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin...
CVE-2025-52023MEDIUM5.3A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to t...
CVE-2025-52022MEDIUM5.3A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers ...
CVE-2025-67264HIGH7.8An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pr...
CVE-2025-70986HIGH7.5Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access ...
CVE-2025-70985CRITICAL9.1Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data...
CVE-2025-70983CRITICAL9.9Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to ...
CVE-2025-14947MEDIUM6.5The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-71177MEDIUM5.4LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package crea...
CVE-2025-67231MEDIUM5.9A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary ...
CVE-2025-67230HIGH7.1Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with rendere...
CVE-2025-67229CRITICAL9.8An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauth...
CVE-2025-71161MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correcti...
CVE-2025-71160MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: avoid chain re-validation if ...
CVE-2025-71159HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free warning in btrfs_get_or_c...
CVE-2025-71158MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IR...
CVE-2025-69908HIGH7.5An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged...
CVE-2025-67125MEDIUM4.4A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern::match in docopt_private.h) when merging occurrence counters...
CVE-2025-67124MEDIUM6.8A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an atta...
CVE-2025-66720HIGH7.5Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePolicie...
CVE-2025-66719CRITICAL9.1An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck...
CVE-2025-71157HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/core: always drop device refcount in ib_del_su...
CVE-2025-71156HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gve: defer interrupt enabling until NAPI registrati...
CVE-2025-71155HIGH7.8In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix gmap_helper_zap_one_page() again A ...
CVE-2025-71154MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix memory leak on usb_submit_ur...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now