2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11177HIGH7.5The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, an...
CVE-2025-10754HIGH7.2The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-10743HIGH7.5The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and includi...
CVE-2025-10313HIGH7.2The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scriptin...
CVE-2025-10299HIGH8.8The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation du...
CVE-2025-10293HIGH8.8The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account ta...
CVE-2025-10051HIGH7.2The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-61941HIGH8.6A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered b...
CVE-2025-40000HIGH8.8In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix use-after-free in rtw89_core_tx_ki...
CVE-2025-39998HIGH7.1In the Linux kernel, the following vulnerability has been resolved: scsi: target: target_core_configfs: Add length chec...
CVE-2025-39994HIGH7.3In the Linux kernel, the following vulnerability has been resolved: media: tuner: xc5000: Fix use-after-free in xc5000_...
CVE-2025-39993HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot...
CVE-2025-39990HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Check the helper function is valid in get_help...
CVE-2025-39988HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: populate ndo_change_mtu() to preve...
CVE-2025-39987HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: hi311x: populate ndo_change_mtu() to prevent b...
CVE-2025-39986HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: sun4i_can: populate ndo_change_mtu() to preven...
CVE-2025-39985HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: mcba_usb: populate ndo_change_mtu() to prevent...
CVE-2025-39983HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeu...
CVE-2025-39982HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_acl_create_con...
CVE-2025-39981HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix possible UAFs This attemps to...
CVE-2025-39979HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, fix UAF in flow counter release Fix ...
CVE-2025-39978HIGH7.8In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix potential use after free in otx2_...
CVE-2025-39977HIGH7.8In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI sy...
CVE-2025-39976HIGH7.8In the Linux kernel, the following vulnerability has been resolved: futex: Use correct exit on failure from futex_hash_...
CVE-2025-39973HIGH8.8In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now