2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14042 | MEDIUM | 6.4 | 0.2% | May 29, 2026 | The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2025-11993 | HIGH | 8.8 | 0.4% | May 29, 2026 | The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve... |
| CVE-2025-48977 | MEDIUM | 6.5 | 0.5% | May 28, 2026 | Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the ... |
| CVE-2025-69600 | HIGH | 7.8 | 0.8% | May 27, 2026 | Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execut... |
| CVE-2025-67903 | MEDIUM | 5.3 | 0.2% | May 27, 2026 | Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass. |
| CVE-2025-70116 | MEDIUM | 4.3 | 0.4% | May 27, 2026 | A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can r... |
| CVE-2025-68712 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerp... |
| CVE-2025-70103 | HIGH | 7.3 | 0.4% | May 27, 2026 | Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function i... |
| CVE-2025-71312 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_... |
| CVE-2025-71311 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN r... |
| CVE-2025-71309 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix deadlock in ni_read_folio_cmpr Syzbo... |
| CVE-2025-71308 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix potential NULL pointer dereferen... |
| CVE-2025-71307 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NULL pointer dereference on pantho... |
| CVE-2025-71306 | HIGH | 7.1 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: ima: Fix stack-out-of-bounds in is_bprm_creds_for_e... |
| CVE-2025-71305 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/display/dp_mst: Add protection against 0 vcpi ... |
| CVE-2025-71304 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: smack: /smack/doi: accept previously used values W... |
| CVE-2025-71303 | MEDIUM | 4.7 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix race condition when checking rpm... |
| CVE-2025-3633 | HIGH | 8.2 | 0.3% | May 27, 2026 | IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable... |
| CVE-2025-0898 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and ... |
| CVE-2025-66593 | MEDIUM | 5.6 | 0.1% | May 27, 2026 | An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary ... |
| CVE-2025-66592 | MEDIUM | 5.6 | 0.1% | May 27, 2026 | An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local use... |
| CVE-2025-52747 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Themebox -... |
| CVE-2025-30028 | HIGH | 8.6 | 0.4% | May 27, 2026 | A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files. |
| CVE-2025-22741 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Felan Fr... |
| CVE-2025-14713 | HIGH | 7.5 | 0.5% | May 27, 2026 | An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now