2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71153MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix memory leak in get_file_all_info() In g...
CVE-2025-71152HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: dsa: properly keep track of conduit reference ...
CVE-2025-71151MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3_recon...
CVE-2025-71150MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix refcount leak when invalid session is fo...
CVE-2025-71149——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71148LOW3.3In the Linux kernel, the following vulnerability has been resolved: net/handshake: restore destructor on submit failure...
CVE-2025-71147MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd ...
CVE-2025-71146MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error pat...
CVE-2025-69907HIGH7.5An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and acce...
CVE-2025-71145HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: phy: isp1301: fix non-OF device reference imba...
CVE-2025-13921MEDIUM4.3The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unau...
CVE-2025-4320CRITICAL10Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Bire...
CVE-2025-4319CRITICAL9.4Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne...
CVE-2025-14866HIGH8.8The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin...
CVE-2025-2204MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tapandsign ...
CVE-2025-46699MEDIUM6.5Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a...
CVE-2025-14745MEDIUM6.4The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored...
CVE-2025-14069MEDIUM6.4The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sas...
CVE-2025-67847HIGH8.8A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbi...
CVE-2025-3839HIGH8A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user in...
CVE-2025-15522MEDIUM6.4The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2025-15351HIGH7.8Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab...
CVE-2025-15350HIGH7.8Anritsu VectorStar CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerab...
CVE-2025-15349HIGH7.5Anritsu ShockLine SCPI Race Condition Remote Code Execution Vulnerability. This vulnerability allows network-adjacent at...
CVE-2025-15348HIGH7.8Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now