2025 CVE Vulnerabilities
45,165 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68331 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when the uas devi... |
| CVE-2025-68330 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: accel: bmc150: Fix irq assumption regression ... |
| CVE-2025-68329 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close ... |
| CVE-2025-68328 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix bug in saving controll... |
| CVE-2025-68327 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Fix synchronous external abort ... |
| CVE-2025-68326 | — | — | 0.2% | Dec 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix stack_depot usage Add missing stac... |
| CVE-2025-67443 | MEDIUM | 6.1 | 0.2% | Dec 22, 2025 | Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the lo... |
| CVE-2025-10021 | HIGH | 7 | 0.1% | Dec 22, 2025 | A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 20... |
| CVE-2025-67826 | HIGH | 7.7 | 0.1% | Dec 22, 2025 | An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ul... |
| CVE-2025-61740 | HIGH | 7.2 | 0.1% | Dec 22, 2025 | Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-ser... |
| CVE-2025-26379 | HIGH | 7.2 | 0.2% | Dec 22, 2025 | Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets. |
| CVE-2025-14018 | HIGH | 7.3 | 0.4% | Dec 22, 2025 | Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating ... |
| CVE-2025-14273 | HIGH | 8.3 | 0.2% | Dec 22, 2025 | Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enab... |
| CVE-2025-8460 | MEDIUM | 4.8 | 0.2% | Dec 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-61739 | HIGH | 7.2 | 0.2% | Dec 22, 2025 | Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets. |
| CVE-2025-61738 | LOW | 2.3 | 0.2% | Dec 22, 2025 | Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network... |
| CVE-2025-54890 | MEDIUM | 4.8 | 0.2% | Dec 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-12514 | HIGH | 7.2 | 0.3% | Dec 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon... |
| CVE-2025-62880 | MEDIUM | 4.3 | 0.1% | Dec 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery... |
| CVE-2025-62107 | MEDIUM | 4.3 | 0.1% | Dec 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page feather-login-page allows Cross Site Req... |
| CVE-2025-62094 | MEDIUM | 6.5 | 0.1% | Dec 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidthemes Void El... |
| CVE-2025-8305 | MEDIUM | 6.5 | 0.1% | Dec 22, 2025 | An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen... |
| CVE-2025-8304 | MEDIUM | 6.5 | 0.1% | Dec 22, 2025 | An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen... |
| CVE-2025-11545 | CRITICAL | 9.5 | 0.3% | Dec 22, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions proj... |
| CVE-2025-11544 | CRITICAL | 9.5 | 0.3% | Dec 22, 2025 | Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now