2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46422 | HIGH | 7.8 | 0.5% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-43942 | HIGH | 7.8 | 0.6% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-43941 | HIGH | 7.8 | 0.7% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-43940 | HIGH | 7.8 | 0.6% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-43939 | HIGH | 7.8 | 0.6% | Oct 30, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-53880 | HIGH | 8.7 | 0.3% | Oct 30, 2025 | A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent n... |
| CVE-2025-39663 | HIGH | 8.4 | 0.5% | Oct 30, 2025 | Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject ... |
| CVE-2025-54470 | HIGH | 8.6 | 0.2% | Oct 30, 2025 | This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When thi... |
| CVE-2025-40105 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: vfs: Don't leak disconnected dentries on umount Wh... |
| CVE-2025-40104 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix mailbox API compatibility by negotiati... |
| CVE-2025-40096 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix potential double free in drm_sched_j... |
| CVE-2025-40095 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Refactor bind path to use __f... |
| CVE-2025-40094 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_acm: Refactor bind path to use __fre... |
| CVE-2025-40093 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ecm: Refactor bind path to use __fre... |
| CVE-2025-40092 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Refactor bind path to use __fre... |
| CVE-2025-40088 | HIGH | 7.1 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_str... |
| CVE-2025-40087 | HIGH | 7.5 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Define a proc_layoutcommit for the FlexFiles ... |
| CVE-2025-62230 | HIGH | 7.3 | 0.3% | Oct 30, 2025 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The soft... |
| CVE-2025-62229 | HIGH | 7.3 | 0.5% | Oct 30, 2025 | A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error ... |
| CVE-2025-62231 | HIGH | 7.3 | 0.3% | Oct 30, 2025 | A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCom... |
| CVE-2025-9954 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.... |
| CVE-2025-12466 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect ... |
| CVE-2025-12082 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects Civ... |
| CVE-2025-61725 | HIGH | 7.5 | 0.6% | Oct 29, 2025 | The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsi... |
| CVE-2025-61723 | HIGH | 7.5 | 0.6% | Oct 29, 2025 | The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now