2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39959 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: Fix incorrect retrival of acp_chip_... |
| CVE-2025-39956 | MEDIUM | 5.5 | 0.2% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error Whe... |
| CVE-2025-39954 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: mp: Fix dual-divider clock rate read... |
| CVE-2025-27049 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | Transient DOS while processing IOCTL call for image encoding. |
| CVE-2025-27045 | MEDIUM | 6.1 | 0.1% | Oct 9, 2025 | Information disclosure while processing batch command execution in Video driver. |
| CVE-2025-27041 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | Transient DOS while processing video packets received from video firmware. |
| CVE-2025-27040 | MEDIUM | 6.5 | 0.1% | Oct 9, 2025 | Information disclosure may occur while processing the hypervisor log. |
| CVE-2025-27039 | MEDIUM | 6.6 | 0.1% | Oct 9, 2025 | Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request. |
| CVE-2025-11166 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all ... |
| CVE-2025-11512 | MEDIUM | 6.1 | 0.4% | Oct 9, 2025 | A vulnerability was found in code-projects Voting System 1.0. Affected by this issue is some unknown functionality of th... |
| CVE-2025-11495 | MEDIUM | 5.5 | 0.2% | Oct 8, 2025 | A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of... |
| CVE-2025-11494 | MEDIUM | 5.5 | 0.2% | Oct 8, 2025 | A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd... |
| CVE-2025-61906 | MEDIUM | 4.3 | 0.3% | Oct 8, 2025 | Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Open... |
| CVE-2025-61788 | MEDIUM | 5.4 | 0.2% | Oct 8, 2025 | Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Open... |
| CVE-2025-42706 | MEDIUM | 6.5 | 0.2% | Oct 8, 2025 | A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute co... |
| CVE-2025-42701 | MEDIUM | 5.6 | 0.1% | Oct 8, 2025 | A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute... |
| CVE-2025-11485 | MEDIUM | 4.8 | 0.3% | Oct 8, 2025 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user... |
| CVE-2025-60318 | MEDIUM | 6.1 | 0.2% | Oct 8, 2025 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi... |
| CVE-2025-59303 | MEDIUM | 6.4 | 0.2% | Oct 8, 2025 | HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snipp... |
| CVE-2025-36636 | MEDIUM | 4.3 | 0.2% | Oct 8, 2025 | In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticat... |
| CVE-2025-61672 | MEDIUM | 5.3 | 0.4% | Oct 8, 2025 | Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3... |
| CVE-2025-60834 | MEDIUM | 6.5 | 0.3% | Oct 8, 2025 | A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying... |
| CVE-2025-60313 | MEDIUM | 6.1 | 0.3% | Oct 8, 2025 | Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input fi... |
| CVE-2025-43771 | MEDIUM | 5.4 | 0.2% | Oct 8, 2025 | Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.... |
| CVE-2025-43724 | MEDIUM | 4.4 | 0.1% | Oct 8, 2025 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerab... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now