2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39853 | HIGH | 7.1 | 0.2% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: i40e: Fix potential invalid access when MAC list is... |
| CVE-2025-39849 | HIGH | 7.8 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: sme: cap SSID length in __cfg80211_... |
| CVE-2025-39841 | HIGH | 7.8 | 0.2% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred... |
| CVE-2025-39840 | HIGH | 7.1 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: audit: fix out-of-bounds read in audit_compare_dnam... |
| CVE-2025-39839 | HIGH | 7.1 | 0.2% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix OOB read/write in network-coding de... |
| CVE-2025-39837 | HIGH | 7.8 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: Fix racy registrations asu... |
| CVE-2025-57528 | HIGH | 7.7 | 0.4% | Sep 19, 2025 | An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of servic... |
| CVE-2025-10712 | HIGH | 7.3 | 0.3% | Sep 19, 2025 | A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This issue affects some unknown processing... |
| CVE-2025-7665 | HIGH | 8.1 | 0.3% | Sep 19, 2025 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missin... |
| CVE-2025-9969 | HIGH | 7.1 | 0.2% | Sep 19, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web D... |
| CVE-2025-10709 | HIGH | 7.5 | 0.9% | Sep 19, 2025 | A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is som... |
| CVE-2025-10708 | HIGH | 7.5 | 0.9% | Sep 19, 2025 | A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by thi... |
| CVE-2025-10707 | HIGH | 8.8 | 0.4% | Sep 19, 2025 | A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessage... |
| CVE-2025-10468 | HIGH | 7.5 | 0.4% | Sep 19, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus ... |
| CVE-2025-9906 | HIGH | 7.3 | 0.2% | Sep 19, 2025 | The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One c... |
| CVE-2025-9905 | HIGH | 7.3 | 0.2% | Sep 19, 2025 | The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One c... |
| CVE-2025-10647 | HIGH | 8.8 | 0.8% | Sep 19, 2025 | The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2025-10458 | HIGH | 7.6 | 0.2% | Sep 19, 2025 | Parameters are not validated or sanitized, and are later used in various internal operations. |
| CVE-2025-10457 | HIGH | 8.1 | 0.4% | Sep 19, 2025 | The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, w... |
| CVE-2025-5955 | HIGH | 8.1 | 0.4% | Sep 19, 2025 | The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inc... |
| CVE-2025-7937 | HIGH | 7.2 | 0.3% | Sep 19, 2025 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can upda... |
| CVE-2025-59713 | HIGH | 8.1 | 0.3% | Sep 19, 2025 | Snipe-IT before 8.1.18 allows unsafe deserialization. |
| CVE-2025-6198 | HIGH | 7.2 | 0.3% | Sep 19, 2025 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up... |
| CVE-2025-59220 | HIGH | 7 | 0.2% | Sep 18, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service... |
| CVE-2025-59216 | HIGH | 7 | 0.2% | Sep 18, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now