2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-40124HIGH7.8In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr...
CVE-2025-40123HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce expected_attach_type for tailcall comp...
CVE-2025-40118HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Fix array-index-out-of-of-bounds on r...
CVE-2025-40117HIGH7.8In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Fix array underflow in pci...
CVE-2025-40112HIGH7.8In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr...
CVE-2025-11994HIGH7.2The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter i...
CVE-2025-59118HIGH7.3Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before ...
CVE-2025-12382HIGH8.8Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows a...
CVE-2025-11962HIGH7.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive ...
CVE-2025-64405HIGH7.5Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att...
CVE-2025-64404HIGH7.5Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice...
CVE-2025-64403HIGH8.1Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing A...
CVE-2025-64401HIGH7.5Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att...
CVE-2025-12903HIGH7.5The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missin...
CVE-2025-12633HIGH7.5The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2025-11560HIGH7.1The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it ba...
CVE-2025-40111HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix Use-after-free in validation Nodes...
CVE-2025-64531HIGH7.8Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-61835HIGH7.8Substance3D - Stager versions 3.1.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability ...
CVE-2025-61834HIGH7.8Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2025-61833HIGH7.8Substance3D - Stager versions 3.1.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft...
CVE-2025-40827HIGH8.5A vulnerability has been identified in Siemens Software Center (All versions < V3.5), Solid Edge SE2025 (All versions < ...
CVE-2025-40817HIGH7.1A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0...
CVE-2025-40816HIGH7.6A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0...
CVE-2025-40815HIGH8.6A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now