2025 CVE Vulnerabilities

45,334 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-38653HIGH7.8In the Linux kernel, the following vulnerability has been resolved: proc: use the same treatment to check proc_lseek as...
CVE-2025-38652HIGH7.1In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.p...
CVE-2025-38636HIGH7.1In the Linux kernel, the following vulnerability has been resolved: rv: Use strings in da monitors tracepoints Using D...
CVE-2025-38627HIGH7.8In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_...
CVE-2025-38620HIGH7.8In the Linux kernel, the following vulnerability has been resolved: zloop: fix KASAN use-after-free of tag set When a ...
CVE-2025-55573HIGH8.8QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2025-33120HIGH7.8IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigure...
CVE-2025-38618HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It ...
CVE-2025-38616HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS UL...
CVE-2025-9259HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9258HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9257HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9256HIGH7.1WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege...
CVE-2025-9255HIGH8.7WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitr...
CVE-2025-57699HIGH8.4Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted ...
CVE-2025-8281HIGH7.1The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2025-41451HIGH8.7Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfo...
CVE-2025-51606HIGH8.8hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with ac...
CVE-2025-55231HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an...
CVE-2025-55230HIGH7.8Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locall...
CVE-2025-54460HIGH7.1The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publicatio...
CVE-2025-51989HIGH7HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an a...
CVE-2025-41415HIGH7.1The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to access publication targets)...
CVE-2025-27721HIGH8.7Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthoriz...
CVE-2025-57751HIGH7.7pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL B...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now