2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11233 | MEDIUM | 6.3 | 0.5% | Oct 1, 2025 | Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cygwin target (`x86_64-pc-cygwin`) didn't correctly handle ... |
| CVE-2025-56514 | MEDIUM | 5.4 | 0.3% | Oct 1, 2025 | Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malic... |
| CVE-2025-59687 | MEDIUM | 4.3 | 0.2% | Oct 1, 2025 | IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details,... |
| CVE-2025-59686 | MEDIUM | 6.5 | 0.2% | Oct 1, 2025 | Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id. |
| CVE-2025-59685 | MEDIUM | 5.3 | 0.3% | Oct 1, 2025 | Kazaar 1.25.12 allows a JWT with none in the alg field. |
| CVE-2025-57275 | MEDIUM | 5.5 | 0.3% | Oct 1, 2025 | Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPD... |
| CVE-2025-41421 | MEDIUM | 4.7 | 0.1% | Oct 1, 2025 | Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of T... |
| CVE-2025-40648 | MEDIUM | 4.8 | 0.3% | Oct 1, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper va... |
| CVE-2025-40647 | MEDIUM | 5.1 | 0.3% | Oct 1, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper va... |
| CVE-2025-39928 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: ensure data length is within supporte... |
| CVE-2025-39927 | MEDIUM | 4.7 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix race condition validating r_parent before... |
| CVE-2025-39926 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: genetlink: fix genl_bind() invoking bind() after -E... |
| CVE-2025-39925 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: can: j1939: implement NETDEV_UNREGISTER notificatio... |
| CVE-2025-39924 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix invalid algorithm for encoded extents T... |
| CVE-2025-39923 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: bam_dma: Fix DT error handling for... |
| CVE-2025-39921 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: microchip-core-qspi: stop checking viability o... |
| CVE-2025-39920 | MEDIUM | 5.5 | 0.2% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: pcmcia: Add error handling for add_interval() in do... |
| CVE-2025-39919 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: add missing check for rx wcid e... |
| CVE-2025-39918 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix linked list corruption Never leave... |
| CVE-2025-39916 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/reclaim: avoid divide-by-zero in damon_rec... |
| CVE-2025-39915 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: phy: transfer phy_config_inband() locking resp... |
| CVE-2025-39914 | MEDIUM | 5.5 | 0.2% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: Silence warning when chunk allocation fail... |
| CVE-2025-39912 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: nfs/localio: restore creds before releasing pageio ... |
| CVE-2025-39910 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc, mm/kasan: respect gfp mask in kasan_pop... |
| CVE-2025-39909 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: avoid divide-by-zero in damon_lr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now