2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40124 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr... |
| CVE-2025-40123 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce expected_attach_type for tailcall comp... |
| CVE-2025-40118 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Fix array-index-out-of-of-bounds on r... |
| CVE-2025-40117 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Fix array underflow in pci... |
| CVE-2025-40112 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr... |
| CVE-2025-11994 | HIGH | 7.2 | 0.3% | Nov 12, 2025 | The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter i... |
| CVE-2025-59118 | HIGH | 7.3 | 1.6% | Nov 12, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before ... |
| CVE-2025-12382 | HIGH | 8.8 | 0.5% | Nov 12, 2025 | Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows a... |
| CVE-2025-11962 | HIGH | 7.3 | 0.2% | Nov 12, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive ... |
| CVE-2025-64405 | HIGH | 7.5 | 1.3% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-64404 | HIGH | 7.5 | 1.2% | Nov 12, 2025 | Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice... |
| CVE-2025-64403 | HIGH | 8.1 | 1.3% | Nov 12, 2025 | Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing A... |
| CVE-2025-64401 | HIGH | 7.5 | 0.8% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-12903 | HIGH | 7.5 | 0.4% | Nov 12, 2025 | The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missin... |
| CVE-2025-12633 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2025-11560 | HIGH | 7.1 | 0.1% | Nov 12, 2025 | The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it ba... |
| CVE-2025-40111 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix Use-after-free in validation Nodes... |
| CVE-2025-64531 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2025-61835 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | Substance3D - Stager versions 3.1.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability ... |
| CVE-2025-61834 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2025-61833 | HIGH | 7.8 | 0.2% | Nov 11, 2025 | Substance3D - Stager versions 3.1.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft... |
| CVE-2025-40827 | HIGH | 8.5 | 0.1% | Nov 11, 2025 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5), Solid Edge SE2025 (All versions < ... |
| CVE-2025-40817 | HIGH | 7.1 | 0.2% | Nov 11, 2025 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0... |
| CVE-2025-40816 | HIGH | 7.6 | 0.2% | Nov 11, 2025 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0... |
| CVE-2025-40815 | HIGH | 8.6 | 0.3% | Nov 11, 2025 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now