2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-38699HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Double-free fix When the bfad_im_probe(...
CVE-2025-38697HIGH7.8In the Linux kernel, the following vulnerability has been resolved: jfs: upper bound check of tree index in dbAllocAG ...
CVE-2025-38688HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iommufd: Prevent ALIGN() overflow When allocating ...
CVE-2025-38685HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imag...
CVE-2025-38682HIGH7.8In the Linux kernel, the following vulnerability has been resolved: i2c: core: Fix double-free of fwnode in i2c_unregis...
CVE-2025-38680HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in u...
CVE-2025-38679HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload b...
CVE-2025-23258HIGH7.3NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker wit...
CVE-2025-23257HIGH7.3NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privile...
CVE-2025-23256HIGH8.7NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause i...
CVE-2025-57263HIGH7.2An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious...
CVE-2025-7388HIGH8.4It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing a...
CVE-2025-9942HIGH8.8A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the fi...
CVE-2025-9941HIGH8.8A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /regi...
CVE-2025-9938HIGH8.8A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the ...
CVE-2025-9519HIGH7.2The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 v...
CVE-2025-9518HIGH7.2The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on...
CVE-2025-9517HIGH7.2The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 ...
CVE-2025-6984HIGH7.5The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE...
CVE-2025-6085HIGH7.2The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validatio...
CVE-2025-58358HIGH7.5Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain ...
CVE-2025-58355HIGH7.7Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or over...
CVE-2025-58057HIGH7.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan...
CVE-2025-43772HIGH7.1Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older u...
CVE-2025-36907HIGH7.3In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer ove...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now