2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40350CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix generating skb from non-linear x...
CVE-2025-40349HIGH7.8In the Linux kernel, the following vulnerability has been resolved: hfs: validate record offset in hfsplus_bmap_alloc ...
CVE-2025-40348In the Linux kernel, the following vulnerability has been resolved: slab: Avoid race on slab->obj_exts in alloc_slab_ob...
CVE-2025-40347HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix the deadlock of enetc_mdio_lock Af...
CVE-2025-40346In the Linux kernel, the following vulnerability has been resolved: arch_topology: Fix incorrect error check in topolog...
CVE-2025-65076MEDIUM6.1WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-65075MEDIUM6.5WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-65074HIGH7.2WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-14780MEDIUM6.3A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknow...
CVE-2025-14443MEDIUM6.4A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, ...
CVE-2025-13741MEDIUM4.3The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo...
CVE-2025-13474HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation o...
CVE-2025-11220MEDIUM6.4The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all...
CVE-2025-0836MEDIUM6.3Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management S...
CVE-2025-14002HIGH8.1The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and ...
CVE-2025-68088MEDIUM5.4Missing Authorization vulnerability in merkulove Huger for Elementor huger-elementor allows Exploiting Incorrectly Confi...
CVE-2025-68087MEDIUM5.4Missing Authorization vulnerability in merkulove Modalier for Elementor modalier-elementor allows Exploiting Incorrectly...
CVE-2025-68086MEDIUM5.4Missing Authorization vulnerability in merkulove Reformer for Elementor reformer-elementor allows Exploiting Incorrectly...
CVE-2025-68085MEDIUM5.4Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly...
CVE-2025-68084MEDIUM5.4Missing Authorization vulnerability in Nitesh Ultimate Auction ultimate-auction allows Exploiting Incorrectly Configure...
CVE-2025-68083MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cro...
CVE-2025-68082MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in SEMrush CY LTD Semrush Content Toolkit semrush-contentshake allows Cr...
CVE-2025-68080MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal User Av...
CVE-2025-68079MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salien...
CVE-2025-68078MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salien...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now