2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-39701HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version che...
CVE-2025-39691HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fs/buffer: fix use-after-free when call bh_read() h...
CVE-2025-39689HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ftrace: Also allocate and copy hash for reading of ...
CVE-2025-39687HIGH7.1In the Linux kernel, the following vulnerability has been resolved: iio: light: as73211: Ensure buffer holes are zeroed...
CVE-2025-39686HIGH7.8In the Linux kernel, the following vulnerability has been resolved: comedi: Make insn_rw_emulate_bits() do insn->n samp...
CVE-2025-39685HIGH7.1In the Linux kernel, the following vulnerability has been resolved: comedi: pcl726: Prevent invalid irq number The rep...
CVE-2025-39683HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tracing: Limit access to parser->buffer when trace_...
CVE-2025-39682HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_...
CVE-2025-39680HIGH7.1In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: Fix out-of-bounds bug in rtl9300_i2c_...
CVE-2025-38736HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: Fix PHY address mask in MDI...
CVE-2025-38734HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF on smcsk after smc_listen_out() B...
CVE-2025-38731HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix vm_bind_ioctl double free bug If the a...
CVE-2025-30199HIGH7.5ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to ba...
CVE-2025-9999HIGH7.6Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on...
CVE-2025-58214HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-57889HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-53307HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Wor...
CVE-2025-48317HIGH7.5Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-...
CVE-2025-48104HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player al...
CVE-2025-32320HIGH7.8In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local esc...
CVE-2025-32318HIGH8.8In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of ...
CVE-2025-58780HIGH7.2index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by...
CVE-2025-10012HIGH8.8A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown functio...
CVE-2025-58881HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simpl...
CVE-2025-58861HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Stored XSS...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now