2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39950 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/tcp: Fix a NULL pointer dereference when using ... |
| CVE-2025-39949 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: qed: Don't collect too many protection override GRC... |
| CVE-2025-39948 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The i... |
| CVE-2025-39947 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Harden uplink netdev access against devi... |
| CVE-2025-39946 | MEDIUM | 5.5 | 9.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: make sure to abort the stream if headers are b... |
| CVE-2025-39942 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: verify remaining_data_length resp... |
| CVE-2025-39941 | MEDIUM | 4.7 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: zram: fix slot write race condition Parallel concu... |
| CVE-2025-39940 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: dm-stripe: fix a possible integer overflow There's... |
| CVE-2025-39938 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6apm-lpass-dais: Fix NULL pointer dere... |
| CVE-2025-39937 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: rfkill: gpio: Fix crash due to dereferencering... |
| CVE-2025-39936 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Always pass in an error pointer to __... |
| CVE-2025-39934 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm: bridge: anx7625: Fix NULL pointer dereference ... |
| CVE-2025-39933 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data... |
| CVE-2025-39932 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: let smbd_destroy() call disable_work_s... |
| CVE-2025-39931 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_... |
| CVE-2025-39929 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_neg... |
| CVE-2025-9952 | MEDIUM | 6.1 | 0.3% | Oct 4, 2025 | The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to R... |
| CVE-2025-9886 | MEDIUM | 4.3 | 0.2% | Oct 4, 2025 | The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to C... |
| CVE-2025-10383 | MEDIUM | 6.4 | 0.2% | Oct 4, 2025 | The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-9030 | MEDIUM | 5.4 | 0.2% | Oct 4, 2025 | The Majestic Before After Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_label'... |
| CVE-2025-9029 | MEDIUM | 4.3 | 0.2% | Oct 4, 2025 | The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPres... |
| CVE-2025-8726 | MEDIUM | 5.4 | 0.2% | Oct 4, 2025 | The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including,... |
| CVE-2025-61962 | MEDIUM | 5.9 | 0.4% | Oct 4, 2025 | In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed... |
| CVE-2025-11228 | MEDIUM | 5.3 | 0.3% | Oct 4, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2025-11227 | MEDIUM | 6.5 | 0.3% | Oct 4, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now