2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-40204HIGH8.1In the Linux kernel, the following vulnerability has been resolved: sctp: Fix MAC comparison to be constant-time To pr...
CVE-2025-40203HIGH7.8In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace se...
CVE-2025-40202HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit...
CVE-2025-40201HIGH7.8In the Linux kernel, the following vulnerability has been resolved: kernel/sys.c: fix the racy usage of task_lock(tsk->...
CVE-2025-40199HIGH7.8In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix PP_MAGIC_MASK to avoid crashing on s...
CVE-2025-40198HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: avoid potential buffer over-read in parse_app...
CVE-2025-40190HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in ...
CVE-2025-40187HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_dispositio...
CVE-2025-40186HIGH8.1In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn...
CVE-2025-40183HIGH7.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4...
CVE-2025-40182HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: skcipher - Fix reqsize handling Commit afd...
CVE-2025-46608HIGH7.2Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged a...
CVE-2025-13063HIGH7.3A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead...
CVE-2025-13061HIGH8.8A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /ind...
CVE-2025-8485HIGH7.3An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to ex...
CVE-2025-46428HIGH8.8Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used...
CVE-2025-46427HIGH8.8Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used ...
CVE-2025-12048HIGH7.7An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessm...
CVE-2025-10495HIGH7.7A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zon...
CVE-2025-64099HIGH8.1Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_...
CVE-2025-63929HIGH7.5A null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple thr...
CVE-2025-63679HIGH7.5free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP mes...
CVE-2025-61667HIGH7The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog L...
CVE-2025-57310HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admi...
CVE-2025-65002HIGH7.5Fujitsu / Fsas Technologies iRMC S6 on M5 before 1.37S mishandles Redfish/WebUI access if the length of a username is ex...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now