2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15033MEDIUM6.5A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on si...
CVE-2025-68645HIGH8.8A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 ...
CVE-2025-67289CRITICAL9.6An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execut...
CVE-2025-65270MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote ...
CVE-2025-68337HIGH7.5In the Linux kernel, the following vulnerability has been resolved: jbd2: avoid bug_on in jbd2_journal_get_create_acces...
CVE-2025-68336HIGH7.5In the Linux kernel, the following vulnerability has been resolved: locking/spinlock/debug: Fix data-race in do_raw_wri...
CVE-2025-68335——In the Linux kernel, the following vulnerability has been resolved: comedi: pcl818: fix null-ptr-deref in pcl818_ai_can...
CVE-2025-68334——In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Add support for Van Gogh SoC ...
CVE-2025-68333MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix possible deadlock in the deferred_ir...
CVE-2025-68332——In the Linux kernel, the following vulnerability has been resolved: comedi: c6xdigio: Fix invalid PNP driver unregistra...
CVE-2025-68331——In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when the uas devi...
CVE-2025-68330——In the Linux kernel, the following vulnerability has been resolved: iio: accel: bmc150: Fix irq assumption regression ...
CVE-2025-68329——In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close ...
CVE-2025-68328——In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix bug in saving controll...
CVE-2025-68327——In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Fix synchronous external abort ...
CVE-2025-68326——In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Fix stack_depot usage Add missing stac...
CVE-2025-67443MEDIUM6.1Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the lo...
CVE-2025-10021HIGH7A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 20...
CVE-2025-67826HIGH7.7An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ul...
CVE-2025-61740HIGH7.2Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-ser...
CVE-2025-26379HIGH7.2Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.
CVE-2025-14018HIGH7.3Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating ...
CVE-2025-14273HIGH8.3Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enab...
CVE-2025-8460MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-61739HIGH7.2Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now