2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-20341HIGH8.8A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate priv...
CVE-2025-13121HIGH7.3A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/a...
CVE-2025-64511HIGH8.8MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network serv...
CVE-2025-64740HIGH7.8Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an...
CVE-2025-64739HIGH7.5External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure ...
CVE-2025-62483HIGH7.5Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated use...
CVE-2025-12765HIGH7.4pgAdmin <= 9.9  is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate ver...
CVE-2025-12764HIGH7.5pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker t...
CVE-2025-12763HIGH8.8pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused ...
CVE-2025-12844HIGH7.1The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to,...
CVE-2025-12733HIGH8.8The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe...
CVE-2025-11923HIGH8.8The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalati...
CVE-2025-64523HIGH8.8File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-64500HIGH7.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundati...
CVE-2025-40206HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefma...
CVE-2025-40205HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encod...
CVE-2025-40204HIGH8.1In the Linux kernel, the following vulnerability has been resolved: sctp: Fix MAC comparison to be constant-time To pr...
CVE-2025-40203HIGH7.8In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace se...
CVE-2025-40202HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit...
CVE-2025-40201HIGH7.8In the Linux kernel, the following vulnerability has been resolved: kernel/sys.c: fix the racy usage of task_lock(tsk->...
CVE-2025-40199HIGH7.8In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix PP_MAGIC_MASK to avoid crashing on s...
CVE-2025-40198HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: avoid potential buffer over-read in parse_app...
CVE-2025-40190HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in ...
CVE-2025-40187HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_dispositio...
CVE-2025-40186HIGH8.1In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now