2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-39841HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred...
CVE-2025-39840HIGH7.1In the Linux kernel, the following vulnerability has been resolved: audit: fix out-of-bounds read in audit_compare_dnam...
CVE-2025-39839HIGH7.1In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix OOB read/write in network-coding de...
CVE-2025-39837HIGH7.8In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: Fix racy registrations asu...
CVE-2025-57528HIGH7.7An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of servic...
CVE-2025-10712HIGH7.3A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This issue affects some unknown processing...
CVE-2025-7665HIGH8.1The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missin...
CVE-2025-9969HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web D...
CVE-2025-10709HIGH7.5A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is som...
CVE-2025-10708HIGH7.5A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by thi...
CVE-2025-10707HIGH8.8A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessage...
CVE-2025-10468HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus ...
CVE-2025-9906HIGH7.3The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One c...
CVE-2025-9905HIGH7.3The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One c...
CVE-2025-10647HIGH8.8The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2025-10458HIGH7.6Parameters are not validated or sanitized, and are later used in various internal operations.
CVE-2025-10457HIGH8.1The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, w...
CVE-2025-5955HIGH8.1The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inc...
CVE-2025-7937HIGH7.2There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can upda...
CVE-2025-59713HIGH8.1Snipe-IT before 8.1.18 allows unsafe deserialization.
CVE-2025-6198HIGH7.2There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up...
CVE-2025-59220HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service...
CVE-2025-59216HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon...
CVE-2025-59215HIGH7Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-54860HIGH7.7Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow manage...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now