2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40155 | HIGH | 7.3 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: debugfs: Fix legacy mode page table dum... |
| CVE-2025-40151 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: No support of struct argument in tr... |
| CVE-2025-40149 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: Use __sk_dst_get() and dst_dev_rcu() in get_ne... |
| CVE-2025-40141 | HIGH | 8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix possible UAF on iso_conn_free ... |
| CVE-2025-40140 | HIGH | 8.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: usb: Remove disruptive netif_wake_queue in rtl... |
| CVE-2025-40139 | HIGH | 7.8 | 0.1% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc... |
| CVE-2025-40135 | HIGH | 8.1 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_xmit() Use RCU in ip6_xmit() ... |
| CVE-2025-40133 | HIGH | 8.1 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: mptcp: Use __sk_dst_get() and dst_dev_rcu() in mptc... |
| CVE-2025-40129 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix null pointer dereference on zero-length... |
| CVE-2025-40124 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr... |
| CVE-2025-40123 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce expected_attach_type for tailcall comp... |
| CVE-2025-40118 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Fix array-index-out-of-of-bounds on r... |
| CVE-2025-40117 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Fix array underflow in pci... |
| CVE-2025-40112 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr... |
| CVE-2025-11994 | HIGH | 7.2 | 0.3% | Nov 12, 2025 | The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter i... |
| CVE-2025-59118 | HIGH | 7.3 | 1.6% | Nov 12, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before ... |
| CVE-2025-12382 | HIGH | 8.8 | 0.5% | Nov 12, 2025 | Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows a... |
| CVE-2025-11962 | HIGH | 7.3 | 0.2% | Nov 12, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive ... |
| CVE-2025-64405 | HIGH | 7.5 | 1.3% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-64404 | HIGH | 7.5 | 1.2% | Nov 12, 2025 | Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice... |
| CVE-2025-64403 | HIGH | 8.1 | 1.3% | Nov 12, 2025 | Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing A... |
| CVE-2025-64401 | HIGH | 7.5 | 0.8% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-12903 | HIGH | 7.5 | 0.4% | Nov 12, 2025 | The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missin... |
| CVE-2025-12633 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2025-11560 | HIGH | 7.1 | 0.1% | Nov 12, 2025 | The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it ba... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now