2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68038 | HIGH | 7.2 | 0.4% | Dec 24, 2025 | Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object I... |
| CVE-2025-67909 | HIGH | 7.5 | 0.3% | Dec 24, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-wo... |
| CVE-2025-67633 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brownbagmarketing ... |
| CVE-2025-67632 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Plugin Factory... |
| CVE-2025-67631 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecommerce Platform... |
| CVE-2025-67630 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webheadcoder WH Tw... |
| CVE-2025-67629 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basticom Basticom ... |
| CVE-2025-67628 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AMP-MODE Review Di... |
| CVE-2025-67627 | MEDIUM | 5.9 | 0.2% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TouchOfTech Draft ... |
| CVE-2025-67625 | MEDIUM | 4.3 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in tmtraderunner Trade Runner traderunner allows Cross Site Request Forg... |
| CVE-2025-67623 | MEDIUM | 5.4 | 0.2% | Dec 24, 2025 | Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Reques... |
| CVE-2025-67622 | HIGH | 7.1 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Store... |
| CVE-2025-67621 | MEDIUM | 4.3 | 0.2% | Dec 24, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in 10up Eight Day Week Print Wo... |
| CVE-2025-68734 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: isdn: mISDN: hfcsusb: fix memory leak in hfcsusb_pr... |
| CVE-2025-68733 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: smack: fix bug: unprivileged task can create labels... |
| CVE-2025-68732 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix race in syncpt alloc/free Fix rac... |
| CVE-2025-68731 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix an integer overflow in aie2_quer... |
| CVE-2025-68730 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix page fault in ivpu_bo_unbind_all_bo... |
| CVE-2025-68729 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix MSDU buffer types handling in RX ... |
| CVE-2025-68728 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: ntfs3: fix uninit memory after failed mi_read in mi... |
| CVE-2025-68727 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: ntfs3: Fix uninit buffer allocated by __getname() ... |
| CVE-2025-68726 | CRITICAL | 9.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: aead - Fix reqsize handling Commit afddce1... |
| CVE-2025-68725 | MEDIUM | 5.5 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Do not let BPF test infra emit invalid GSO typ... |
| CVE-2025-68724 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - prevent overflow in asymm... |
| CVE-2025-68380 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix peer HE MCS assignment In ath11k... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now