2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14042MEDIUM6.4The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-11993HIGH8.8The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve...
CVE-2025-48977MEDIUM6.5Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the ...
CVE-2025-69600HIGH7.8Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execut...
CVE-2025-67903MEDIUM5.3Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
CVE-2025-70116MEDIUM4.3A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can r...
CVE-2025-68712MEDIUM5.5SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerp...
CVE-2025-70103HIGH7.3Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function i...
CVE-2025-71312MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_...
CVE-2025-71311MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN r...
CVE-2025-71309MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix deadlock in ni_read_folio_cmpr Syzbo...
CVE-2025-71308MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix potential NULL pointer dereferen...
CVE-2025-71307MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NULL pointer dereference on pantho...
CVE-2025-71306HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ima: Fix stack-out-of-bounds in is_bprm_creds_for_e...
CVE-2025-71305MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/display/dp_mst: Add protection against 0 vcpi ...
CVE-2025-71304MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smack: /smack/doi: accept previously used values W...
CVE-2025-71303MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix race condition when checking rpm...
CVE-2025-3633HIGH8.2IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable...
CVE-2025-0898MEDIUM6.5The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and ...
CVE-2025-66593MEDIUM5.6An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary ...
CVE-2025-66592MEDIUM5.6An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local use...
CVE-2025-52747HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Themebox -...
CVE-2025-30028HIGH8.6A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
CVE-2025-22741HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Felan Fr...
CVE-2025-14713HIGH7.5An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now