2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-40044HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fs: udf: fix OOB read in lengthAllocDescs handling ...
CVE-2025-40043HIGH8.8In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Add parameter validation for packet ...
CVE-2025-40041HIGH7.8In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Sign-extend struct ops return value...
CVE-2025-40038HIGH7.1In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Skip fastpath emulation on VM-Exit if nex...
CVE-2025-41090HIGH7.6microCLAUDIA in v3.2.0 and prior has an improper access control vulnerability. This flaw allows an authenticated user t...
CVE-2025-40028HIGH7.8In the Linux kernel, the following vulnerability has been resolved: binder: fix double-free in dbitmap A process might...
CVE-2025-40027HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/9p: fix double req put in p9_fd_cancelled Syzk...
CVE-2025-40026HIGH7.9In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Don't (re)check L1 intercepts when comple...
CVE-2025-40025HIGH7.8In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node footer for non...
CVE-2025-10151HIGH7.2Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource lea...
CVE-2025-10150HIGH8.7Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue a...
CVE-2025-11735HIGH7.5The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via t...
CVE-2025-62777HIGH8.8Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within th...
CVE-2025-12347HIGH8.8A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsi...
CVE-2025-12346HIGH8.8A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/m...
CVE-2025-12342HIGH7.3A flaw has been found in Serdar Bayram Ghost Hot Spot up to 20251014. The affected element is an unknown function of the...
CVE-2025-12341HIGH7.8A vulnerability was detected in ermig1979 AntiDupl up to 2.3.12. Impacted is an unknown function of the file AntiDupl.NE...
CVE-2025-43024HIGH7.5A GUI dialog of an application allows to view what files are in the file system without proper authorization.
CVE-2025-62260HIGH7.5Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA thr...
CVE-2025-12331HIGH7.2A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add....
CVE-2025-62725HIGH8.9Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotatio...
CVE-2025-12326HIGH7.5A vulnerability was found in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. This vulnerability affect...
CVE-2025-12322HIGH8.8A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromNatStaticSetting of the file /go...
CVE-2025-61105HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info ...
CVE-2025-61102HIGH7.5FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now