2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-39749HIGH7In the Linux kernel, the following vulnerability has been resolved: rcu: Protect ->defer_qs_iw_pending from data race ...
CVE-2025-39744HIGH7.1In the Linux kernel, the following vulnerability has been resolved: rcu: Fix rcu_read_unlock() deadloop due to IRQ work...
CVE-2025-39743HIGH7.8In the Linux kernel, the following vulnerability has been resolved: jfs: truncate good inode pages when hard link is 0 ...
CVE-2025-39740HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: prevent potential UAF If we hit th...
CVE-2025-39738HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped...
CVE-2025-58145HIGH7.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-58144HIGH7.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-10193HIGH7.4DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protection...
CVE-2025-9018HIGH8.8The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capab...
CVE-2025-58320HIGH7.3Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
CVE-2025-48041HIGH7.1Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive...
CVE-2025-9918HIGH8.7A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3....
CVE-2025-9874HIGH7.5The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i...
CVE-2025-9693HIGH8The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file del...
CVE-2025-9073HIGH7.5The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions ...
CVE-2025-8425HIGH8.8The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e...
CVE-2025-8422HIGH7.5The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all ver...
CVE-2025-8417HIGH8.1The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, ...
CVE-2025-9059HIGH8.8The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hij...
CVE-2025-10236HIGH7.5A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the...
CVE-2025-59052HIGH7.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2025-54376HIGH7.5Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v...
CVE-2025-59049HIGH7.5Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file servi...
CVE-2025-10210HIGH8.8A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modu...
CVE-2025-10201HIGH8.8Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now