2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38708 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in handle_write_conflict... |
| CVE-2025-38707 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add sanity check for file name The lengt... |
| CVE-2025-38704 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthre... |
| CVE-2025-38703 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Make dma-fences compliant with the safe acc... |
| CVE-2025-38702 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: fbdev: fix potential buffer overflow in do_register... |
| CVE-2025-38699 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Double-free fix When the bfad_im_probe(... |
| CVE-2025-38697 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: jfs: upper bound check of tree index in dbAllocAG ... |
| CVE-2025-38688 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Prevent ALIGN() overflow When allocating ... |
| CVE-2025-38685 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imag... |
| CVE-2025-38682 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: i2c: core: Fix double-free of fwnode in i2c_unregis... |
| CVE-2025-38680 | HIGH | 7.1 | 0.2% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in u... |
| CVE-2025-38679 | HIGH | 7.1 | 0.1% | Sep 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload b... |
| CVE-2025-23258 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker wit... |
| CVE-2025-23257 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privile... |
| CVE-2025-23256 | HIGH | 8.7 | 0.1% | Sep 4, 2025 | NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause i... |
| CVE-2025-57263 | HIGH | 7.2 | 0.4% | Sep 4, 2025 | An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious... |
| CVE-2025-7388 | HIGH | 8.4 | 0.9% | Sep 4, 2025 | It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing a... |
| CVE-2025-9942 | HIGH | 8.8 | 0.4% | Sep 4, 2025 | A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the fi... |
| CVE-2025-9941 | HIGH | 8.8 | 0.4% | Sep 4, 2025 | A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /regi... |
| CVE-2025-9938 | HIGH | 8.8 | 1.4% | Sep 4, 2025 | A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the ... |
| CVE-2025-9519 | HIGH | 7.2 | 0.8% | Sep 4, 2025 | The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 v... |
| CVE-2025-9518 | HIGH | 7.2 | 0.9% | Sep 4, 2025 | The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on... |
| CVE-2025-9517 | HIGH | 7.2 | 0.6% | Sep 4, 2025 | The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 ... |
| CVE-2025-6984 | HIGH | 7.5 | 1.5% | Sep 4, 2025 | The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE... |
| CVE-2025-6085 | HIGH | 7.2 | 1.2% | Sep 4, 2025 | The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validatio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now