2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40350 | CRITICAL | 9.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix generating skb from non-linear x... |
| CVE-2025-40349 | HIGH | 7.8 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: hfs: validate record offset in hfsplus_bmap_alloc ... |
| CVE-2025-40348 | — | — | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: slab: Avoid race on slab->obj_exts in alloc_slab_ob... |
| CVE-2025-40347 | HIGH | 7.5 | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix the deadlock of enetc_mdio_lock Af... |
| CVE-2025-40346 | — | — | 0.2% | Dec 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: arch_topology: Fix incorrect error check in topolog... |
| CVE-2025-65076 | MEDIUM | 6.1 | 0.3% | Dec 16, 2025 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser... |
| CVE-2025-65075 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser... |
| CVE-2025-65074 | HIGH | 7.2 | 0.4% | Dec 16, 2025 | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser... |
| CVE-2025-14780 | MEDIUM | 6.3 | 0.2% | Dec 16, 2025 | A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknow... |
| CVE-2025-14443 | MEDIUM | 6.4 | 0.3% | Dec 16, 2025 | A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, ... |
| CVE-2025-13741 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo... |
| CVE-2025-13474 | HIGH | 7.5 | 0.3% | Dec 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation o... |
| CVE-2025-11220 | MEDIUM | 6.4 | 0.2% | Dec 16, 2025 | The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all... |
| CVE-2025-0836 | MEDIUM | 6.3 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management S... |
| CVE-2025-14002 | HIGH | 8.1 | 0.4% | Dec 16, 2025 | The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and ... |
| CVE-2025-68088 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Huger for Elementor huger-elementor allows Exploiting Incorrectly Confi... |
| CVE-2025-68087 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Modalier for Elementor modalier-elementor allows Exploiting Incorrectly... |
| CVE-2025-68086 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Reformer for Elementor reformer-elementor allows Exploiting Incorrectly... |
| CVE-2025-68085 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly... |
| CVE-2025-68084 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | Missing Authorization vulnerability in Nitesh Ultimate Auction ultimate-auction allows Exploiting Incorrectly Configure... |
| CVE-2025-68083 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cro... |
| CVE-2025-68082 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in SEMrush CY LTD Semrush Content Toolkit semrush-contentshake allows Cr... |
| CVE-2025-68080 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal User Av... |
| CVE-2025-68079 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salien... |
| CVE-2025-68078 | MEDIUM | 6.5 | 0.1% | Dec 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salien... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now