2025 CVE Vulnerabilities

45,327 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68282——In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: fix use-after-free in usb_gadget_...
CVE-2025-68269MEDIUM5.4In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
CVE-2025-68268MEDIUM6.1In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
CVE-2025-68267MEDIUM6.5In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token in...
CVE-2025-68166MEDIUM6.1In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
CVE-2025-68165MEDIUM6.1In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
CVE-2025-68164LOW2.7In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
CVE-2025-68163MEDIUM4.8In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
CVE-2025-68162LOW2.7In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
CVE-2025-65427MEDIUM6.5An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not impleme...
CVE-2025-65319CRITICAL9.1When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system with...
CVE-2025-65318CRITICAL9.1When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system witho...
CVE-2025-64012MEDIUM4.3InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify owners...
CVE-2025-62329MEDIUM5.6HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which ma...
CVE-2025-14432MEDIUM4.9In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC...
CVE-2025-10450HIGH7.5Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Librar...
CVE-2025-68281——In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: bug fix while parsing mipi-sdca-control...
CVE-2025-68266——In the Linux kernel, the following vulnerability has been resolved: bfs: Reconstruct file type when loading from disk ...
CVE-2025-68265HIGH7.8In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin request_queue lifetime The namespa...
CVE-2025-68264——In the Linux kernel, the following vulnerability has been resolved: ext4: refresh inline data size before write operati...
CVE-2025-68263CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_requ...
CVE-2025-68262——In the Linux kernel, the following vulnerability has been resolved: crypto: zstd - fix double-free in per-CPU stream cl...
CVE-2025-68261HIGH7.5In the Linux kernel, the following vulnerability has been resolved: ext4: add i_data_sem protection in ext4_destroy_inl...
CVE-2025-68260HIGH7.8In the Linux kernel, the following vulnerability has been resolved: rust_binder: fix race condition on death_list Rust...
CVE-2025-68259——In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Don't skip unrelated instruction if INT3/...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now