2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39701 | HIGH | 7.8 | 0.2% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version che... |
| CVE-2025-39691 | HIGH | 7.8 | 0.2% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/buffer: fix use-after-free when call bh_read() h... |
| CVE-2025-39689 | HIGH | 7.8 | 0.2% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: ftrace: Also allocate and copy hash for reading of ... |
| CVE-2025-39687 | HIGH | 7.1 | 0.2% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: light: as73211: Ensure buffer holes are zeroed... |
| CVE-2025-39686 | HIGH | 7.8 | 0.2% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: comedi: Make insn_rw_emulate_bits() do insn->n samp... |
| CVE-2025-39685 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: comedi: pcl726: Prevent invalid irq number The rep... |
| CVE-2025-39683 | HIGH | 7.1 | 0.2% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: Limit access to parser->buffer when trace_... |
| CVE-2025-39682 | HIGH | 7.1 | 0.2% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_... |
| CVE-2025-39680 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: Fix out-of-bounds bug in rtl9300_i2c_... |
| CVE-2025-38736 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: Fix PHY address mask in MDI... |
| CVE-2025-38734 | HIGH | 7.8 | 0.2% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF on smcsk after smc_listen_out() B... |
| CVE-2025-38731 | HIGH | 7.8 | 0.1% | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix vm_bind_ioctl double free bug If the a... |
| CVE-2025-30199 | HIGH | 7.5 | 0.3% | Sep 5, 2025 | ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to ba... |
| CVE-2025-9999 | HIGH | 7.6 | 0.1% | Sep 5, 2025 | Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on... |
| CVE-2025-58214 | HIGH | 8.1 | 0.4% | Sep 5, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-57889 | HIGH | 7.5 | 0.4% | Sep 5, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-53307 | HIGH | 7.1 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Wor... |
| CVE-2025-48317 | HIGH | 7.5 | 0.4% | Sep 5, 2025 | Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-... |
| CVE-2025-48104 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player al... |
| CVE-2025-32320 | HIGH | 7.8 | 0.1% | Sep 5, 2025 | In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local esc... |
| CVE-2025-32318 | HIGH | 8.8 | 0.3% | Sep 5, 2025 | In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of ... |
| CVE-2025-58780 | HIGH | 7.2 | 0.2% | Sep 5, 2025 | index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by... |
| CVE-2025-10012 | HIGH | 8.8 | 0.4% | Sep 5, 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown functio... |
| CVE-2025-58881 | HIGH | 8.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simpl... |
| CVE-2025-58861 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Stored XSS... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now