2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40204 | HIGH | 8.1 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sctp: Fix MAC comparison to be constant-time To pr... |
| CVE-2025-40203 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace se... |
| CVE-2025-40202 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit... |
| CVE-2025-40201 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: kernel/sys.c: fix the racy usage of task_lock(tsk->... |
| CVE-2025-40199 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix PP_MAGIC_MASK to avoid crashing on s... |
| CVE-2025-40198 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: avoid potential buffer over-read in parse_app... |
| CVE-2025-40190 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in ... |
| CVE-2025-40187 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_dispositio... |
| CVE-2025-40186 | HIGH | 8.1 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn... |
| CVE-2025-40183 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4... |
| CVE-2025-40182 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: skcipher - Fix reqsize handling Commit afd... |
| CVE-2025-46608 | HIGH | 7.2 | 0.4% | Nov 12, 2025 | Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged a... |
| CVE-2025-13063 | HIGH | 7.3 | 0.3% | Nov 12, 2025 | A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead... |
| CVE-2025-13061 | HIGH | 8.8 | 0.3% | Nov 12, 2025 | A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /ind... |
| CVE-2025-8485 | HIGH | 7.3 | 0.1% | Nov 12, 2025 | An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to ex... |
| CVE-2025-46428 | HIGH | 8.8 | 1.1% | Nov 12, 2025 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used... |
| CVE-2025-46427 | HIGH | 8.8 | 1.1% | Nov 12, 2025 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used ... |
| CVE-2025-12048 | HIGH | 7.7 | 0.2% | Nov 12, 2025 | An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessm... |
| CVE-2025-10495 | HIGH | 7.7 | 0.2% | Nov 12, 2025 | A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zon... |
| CVE-2025-64099 | HIGH | 8.1 | 0.3% | Nov 12, 2025 | Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_... |
| CVE-2025-63929 | HIGH | 7.5 | 0.3% | Nov 12, 2025 | A null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple thr... |
| CVE-2025-63679 | HIGH | 7.5 | 0.3% | Nov 12, 2025 | free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP mes... |
| CVE-2025-61667 | HIGH | 7 | 0.1% | Nov 12, 2025 | The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog L... |
| CVE-2025-57310 | HIGH | 8.8 | 0.2% | Nov 12, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admi... |
| CVE-2025-65002 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | Fujitsu / Fsas Technologies iRMC S6 on M5 before 1.37S mishandles Redfish/WebUI access if the length of a username is ex... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now