2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65001HIGH8.2Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and avai...
CVE-2025-63811HIGH7.5An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS)...
CVE-2025-59088HIGH8.6If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default...
CVE-2025-2843HIGH8.8A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment...
CVE-2025-13042HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exp...
CVE-2025-11797HIGH7.8A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malici...
CVE-2025-11795HIGH7.8A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ...
CVE-2025-64293HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Golemiq 0 Day Anal...
CVE-2025-11700HIGH7.5N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
CVE-2025-63667HIGH7.5Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attacke...
CVE-2025-11567HIGH7.3CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target inst...
CVE-2025-11565HIGH7.3CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c...
CVE-2025-12998HIGH8.2Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Module...
CVE-2025-40174HIGH7.8In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix SMP ordering in switch_mm_irqs_off() S...
CVE-2025-40173HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/ip6_tunnel: Prevent perpetual tunnel growth Si...
CVE-2025-40172HIGH7.8In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Treat remaining == 0 as error in find_a...
CVE-2025-40171HIGH7.5In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: move lsop put work to nvmet_fc_ls_req_op ...
CVE-2025-40170HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: use dst_dev_rcu() in sk_setup_caps() Use RCU ...
CVE-2025-40169HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative offsets for ALU ops When veri...
CVE-2025-40168HIGH8.1In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_cl...
CVE-2025-40167HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: detect invalid INLINE_DATA + EXTENTS flag com...
CVE-2025-40166HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Check GuC running state before deregist...
CVE-2025-40165HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: nxp: imx8-isi: m2m: Fix streaming cleanup on...
CVE-2025-40159HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xsk: Harden userspace-supplied xdp_desc validation ...
CVE-2025-40158HIGH8.1In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_outpu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now