2025 CVE Vulnerabilities
45,334 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38653 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: proc: use the same treatment to check proc_lseek as... |
| CVE-2025-38652 | HIGH | 7.1 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.p... |
| CVE-2025-38636 | HIGH | 7.1 | 0.1% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: rv: Use strings in da monitors tracepoints Using D... |
| CVE-2025-38627 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_... |
| CVE-2025-38620 | HIGH | 7.8 | 0.1% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: zloop: fix KASAN use-after-free of tag set When a ... |
| CVE-2025-55573 | HIGH | 8.8 | 0.4% | Aug 22, 2025 | QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2025-33120 | HIGH | 7.8 | 0.1% | Aug 22, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigure... |
| CVE-2025-38618 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It ... |
| CVE-2025-38616 | HIGH | 7.1 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS UL... |
| CVE-2025-9259 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9258 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9257 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9256 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9255 | HIGH | 8.7 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitr... |
| CVE-2025-57699 | HIGH | 8.4 | 0.2% | Aug 22, 2025 | Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted ... |
| CVE-2025-8281 | HIGH | 7.1 | 0.2% | Aug 22, 2025 | The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2025-41451 | HIGH | 8.7 | 0.9% | Aug 22, 2025 | Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfo... |
| CVE-2025-51606 | HIGH | 8.8 | 0.3% | Aug 21, 2025 | hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with ac... |
| CVE-2025-55231 | HIGH | 7.5 | 0.4% | Aug 21, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an... |
| CVE-2025-55230 | HIGH | 7.8 | 0.3% | Aug 21, 2025 | Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locall... |
| CVE-2025-54460 | HIGH | 7.1 | 0.3% | Aug 21, 2025 | The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publicatio... |
| CVE-2025-51989 | HIGH | 7 | 0.4% | Aug 21, 2025 | HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an a... |
| CVE-2025-41415 | HIGH | 7.1 | 0.3% | Aug 21, 2025 | The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to access publication targets)... |
| CVE-2025-27721 | HIGH | 8.7 | 0.3% | Aug 21, 2025 | Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthoriz... |
| CVE-2025-57751 | HIGH | 7.7 | 0.3% | Aug 21, 2025 | pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL B... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now