2025 CVE Vulnerabilities

45,165 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68331In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when the uas devi...
CVE-2025-68330In the Linux kernel, the following vulnerability has been resolved: iio: accel: bmc150: Fix irq assumption regression ...
CVE-2025-68329In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close ...
CVE-2025-68328In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix bug in saving controll...
CVE-2025-68327In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Fix synchronous external abort ...
CVE-2025-68326In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix stack_depot usage Add missing stac...
CVE-2025-67443MEDIUM6.1Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the lo...
CVE-2025-10021HIGH7A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 20...
CVE-2025-67826HIGH7.7An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ul...
CVE-2025-61740HIGH7.2Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-ser...
CVE-2025-26379HIGH7.2Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.
CVE-2025-14018HIGH7.3Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating ...
CVE-2025-14273HIGH8.3Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enab...
CVE-2025-8460MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-61739HIGH7.2Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.
CVE-2025-61738LOW2.3Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network...
CVE-2025-54890MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-12514HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon...
CVE-2025-62880MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery...
CVE-2025-62107MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page feather-login-page allows Cross Site Req...
CVE-2025-62094MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidthemes Void El...
CVE-2025-8305MEDIUM6.5An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen...
CVE-2025-8304MEDIUM6.5An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen...
CVE-2025-11545CRITICAL9.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions proj...
CVE-2025-11544CRITICAL9.5Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now