2025 CVE Vulnerabilities

45,160 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-52094HIGH7.8Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via ...
CVE-2025-51605HIGH8.1An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header v...
CVE-2025-50674HIGH7.8An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaV...
CVE-2025-38670HIGH7.1In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_...
CVE-2025-38667HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iio: fix potential out-of-bound write The buffer i...
CVE-2025-38666HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix use-after-free in AARP proxy pr...
CVE-2025-38662HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8365-dai-i2s: pass correct size t...
CVE-2025-38657HIGH7.1In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: mcc: prevent shift wrapping in rtw89_c...
CVE-2025-38656HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_st...
CVE-2025-38653HIGH7.8In the Linux kernel, the following vulnerability has been resolved: proc: use the same treatment to check proc_lseek as...
CVE-2025-38652HIGH7.1In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.p...
CVE-2025-38636HIGH7.1In the Linux kernel, the following vulnerability has been resolved: rv: Use strings in da monitors tracepoints Using D...
CVE-2025-38627HIGH7.8In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_...
CVE-2025-38620HIGH7.8In the Linux kernel, the following vulnerability has been resolved: zloop: fix KASAN use-after-free of tag set When a ...
CVE-2025-55573HIGH8.8QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2025-33120HIGH7.8IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigure...
CVE-2025-38618HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It ...
CVE-2025-38616HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS UL...
CVE-2025-9259HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9258HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9257HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9256HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9255HIGH8.7WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitr...
CVE-2025-57699HIGH8.4Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted ...
CVE-2025-8281HIGH7.1The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the pag...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now