2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68760 | — | — | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix potential out-of-bounds read in iomm... |
| CVE-2025-68759 | — | — | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtl818x: Fix potential memory leaks in rtl818... |
| CVE-2025-68758 | — | — | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: backlight: led-bl: Add devlink to supplier LEDs LE... |
| CVE-2025-68757 | — | — | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/vgem-fence: Fix potential deadlock on release ... |
| CVE-2025-68756 | — | — | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: block: Use RCU in blk_mq_[un]quiesce_tagset() inste... |
| CVE-2025-68755 | — | — | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: most: remove broken i2c driver The MOST I... |
| CVE-2025-68754 | — | — | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: rtc: amlogic-a4: fix double free caused by devm Th... |
| CVE-2025-68753 | HIGH | 7.1 | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: add bounds check in put_user l... |
| CVE-2025-68752 | — | — | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: iavf: Implement settime64 with -EOPNOTSUPP ptp_clo... |
| CVE-2025-68751 | — | — | 0.2% | Jan 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Fix false-positive kmsan report in fpu_vs... |
| CVE-2025-5965 | HIGH | 7.2 | 24.8% | Jan 5, 2026 | In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Imp... |
| CVE-2025-66518 | HIGH | 8.8 | 0.9% | Jan 5, 2026 | Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.ses... |
| CVE-2025-15240 | HIGH | 8.8 | 0.4% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing aut... |
| CVE-2025-15239 | HIGH | 7.1 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate... |
| CVE-2025-15238 | HIGH | 7.1 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticate... |
| CVE-2025-15237 | MEDIUM | 5.3 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat... |
| CVE-2025-15236 | MEDIUM | 5.3 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat... |
| CVE-2025-15235 | HIGH | 7.1 | 0.3% | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing auth... |
| CVE-2025-15022 | MEDIUM | 4.8 | 0.3% | Jan 5, 2026 | Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS)... |
| CVE-2025-15462 | HIGH | 8.8 | 0.9% | Jan 5, 2026 | A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/C... |
| CVE-2025-15461 | HIGH | 8.8 | 0.8% | Jan 5, 2026 | A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/fo... |
| CVE-2025-9543 | LOW | 3.5 | 0.2% | Jan 5, 2026 | The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, w... |
| CVE-2025-15460 | HIGH | 8.8 | 0.6% | Jan 5, 2026 | A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpC... |
| CVE-2025-15459 | HIGH | 8.8 | 0.8% | Jan 5, 2026 | A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of... |
| CVE-2025-14124 | HIGH | 8.6 | 1.6% | Jan 5, 2026 | The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL stat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now