2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68760In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix potential out-of-bounds read in iomm...
CVE-2025-68759In the Linux kernel, the following vulnerability has been resolved: wifi: rtl818x: Fix potential memory leaks in rtl818...
CVE-2025-68758In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to supplier LEDs LE...
CVE-2025-68757In the Linux kernel, the following vulnerability has been resolved: drm/vgem-fence: Fix potential deadlock on release ...
CVE-2025-68756In the Linux kernel, the following vulnerability has been resolved: block: Use RCU in blk_mq_[un]quiesce_tagset() inste...
CVE-2025-68755In the Linux kernel, the following vulnerability has been resolved: staging: most: remove broken i2c driver The MOST I...
CVE-2025-68754In the Linux kernel, the following vulnerability has been resolved: rtc: amlogic-a4: fix double free caused by devm Th...
CVE-2025-68753HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: add bounds check in put_user l...
CVE-2025-68752In the Linux kernel, the following vulnerability has been resolved: iavf: Implement settime64 with -EOPNOTSUPP ptp_clo...
CVE-2025-68751In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Fix false-positive kmsan report in fpu_vs...
CVE-2025-5965HIGH7.2In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Imp...
CVE-2025-66518HIGH8.8Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.ses...
CVE-2025-15240HIGH8.8QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing aut...
CVE-2025-15239HIGH7.1QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate...
CVE-2025-15238HIGH7.1QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate...
CVE-2025-15237MEDIUM5.3QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat...
CVE-2025-15236MEDIUM5.3QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat...
CVE-2025-15235HIGH7.1QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing auth...
CVE-2025-15022MEDIUM4.8Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS)...
CVE-2025-15462HIGH8.8A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/C...
CVE-2025-15461HIGH8.8A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/fo...
CVE-2025-9543LOW3.5The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, w...
CVE-2025-15460HIGH8.8A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpC...
CVE-2025-15459HIGH8.8A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of...
CVE-2025-14124HIGH8.6The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL stat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now