2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39908 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: dev_ioctl: take ops lock in hwtstamp lower pat... |
| CVE-2025-39907 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: stm32_fmc2: avoid overlapping mapping... |
| CVE-2025-39906 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: remove oem i2c adapter on finish ... |
| CVE-2025-39904 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: arm64: kexec: initialize kexec_buf struct in load_o... |
| CVE-2025-39903 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: of_numa: fix uninitialized memory nodes causing ker... |
| CVE-2025-39902 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is i... |
| CVE-2025-39900 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: gen_estimator: fix est_timer() vs CONFIG... |
| CVE-2025-39899 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/userfaultfd: fix kmap_local LIFO ordering for CO... |
| CVE-2025-39897 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Add error handling for RX met... |
| CVE-2025-39895 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched: Fix sched_numa_find_nth_cpu() if mask offlin... |
| CVE-2025-39894 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit... |
| CVE-2025-39893 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: unregister ECC engine on probe... |
| CVE-2025-39892 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: care NULL dirver name on snd_soc_lo... |
| CVE-2025-9512 | MEDIUM | 6.1 | 0.2% | Oct 1, 2025 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modi... |
| CVE-2025-9075 | MEDIUM | 6.4 | 0.2% | Oct 1, 2025 | The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versio... |
| CVE-2025-10744 | MEDIUM | 5.9 | 0.4% | Oct 1, 2025 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposu... |
| CVE-2025-10735 | MEDIUM | 4 | 0.3% | Oct 1, 2025 | The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Reques... |
| CVE-2025-61792 | MEDIUM | 6.4 | 0.1% | Sep 30, 2025 | Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Qu... |
| CVE-2025-55191 | MEDIUM | 5.3 | 0.4% | Sep 30, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1,... |
| CVE-2025-43826 | MEDIUM | 5.4 | 0.2% | Sep 30, 2025 | Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, ... |
| CVE-2025-36262 | MEDIUM | 4.9 | 0.3% | Sep 30, 2025 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to... |
| CVE-2025-36132 | MEDIUM | 5.4 | 0.2% | Sep 30, 2025 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This ... |
| CVE-2025-43827 | MEDIUM | 4.3 | 0.3% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and o... |
| CVE-2025-57254 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allo... |
| CVE-2025-56200 | MEDIUM | 6.1 | 0.3% | Sep 30, 2025 | A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now