2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39886 | MEDIUM | 5.5 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Tell memcg to use allow_spinning=false path in... |
| CVE-2025-39885 | MEDIUM | 5.5 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix recursive semaphore deadlock in fiemap c... |
| CVE-2025-39884 | MEDIUM | 4.7 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix subvolume deletion lockup caused by inod... |
| CVE-2025-39879 | MEDIUM | 5.5 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: ceph: always call ceph_shift_unused_folios_left() ... |
| CVE-2025-39878 | MEDIUM | 5.5 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash after fscrypt_encrypt_pagecache_blo... |
| CVE-2025-39876 | MEDIUM | 5.5 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: fec: Fix possible NPD in fec_enet_phy_reset_af... |
| CVE-2025-39875 | MEDIUM | 5.5 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: igb: Fix NULL pointer dereference in ethtool loopba... |
| CVE-2025-39874 | MEDIUM | 5.5 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: macsec: sync features on RTM_NEWLINK Syzkaller man... |
| CVE-2025-39872 | MEDIUM | 5.5 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: hsr: hold rcu and dev lock for hsr_get_port_ndev h... |
| CVE-2025-8902 | MEDIUM | 6.4 | 0.2% | Sep 23, 2025 | The Widget Options - Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'do_sid... |
| CVE-2025-10837 | MEDIUM | 5.4 | 0.2% | Sep 23, 2025 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerabil... |
| CVE-2025-58915 | MEDIUM | 6.5 | 0.2% | Sep 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design Req... |
| CVE-2025-42907 | MEDIUM | 4.3 | 0.2% | Sep 23, 2025 | SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified... |
| CVE-2025-10827 | MEDIUM | 6.1 | 0.3% | Sep 23, 2025 | A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown fun... |
| CVE-2025-10824 | MEDIUM | 5.3 | 0.1% | Sep 23, 2025 | A vulnerability was determined in axboe fio up to 3.41. This impacts the function __parse_jobs_ini of the file init.c. E... |
| CVE-2025-10822 | MEDIUM | 4.3 | 0.3% | Sep 23, 2025 | A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogControlle... |
| CVE-2025-43814 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, ... |
| CVE-2025-43810 | MEDIUM | 4.3 | 0.3% | Sep 22, 2025 | Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.11... |
| CVE-2025-10821 | MEDIUM | 4.3 | 0.3% | Sep 22, 2025 | A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of ... |
| CVE-2025-10820 | MEDIUM | 4.3 | 0.3% | Sep 22, 2025 | A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /top... |
| CVE-2025-10819 | MEDIUM | 4.3 | 0.3% | Sep 22, 2025 | A security vulnerability has been detected in fuyang_lipengjun platform 1.0. This issue affects the function UserCouponC... |
| CVE-2025-43806 | MEDIUM | 4.3 | 0.2% | Sep 22, 2025 | Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2... |
| CVE-2025-59535 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-57205 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content... |
| CVE-2025-57204 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulne... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now