2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-38570HIGH7.8In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: unlink NAPIs from queues on error to op...
CVE-2025-38568HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: mqprio: fix stack out-of-bounds write in...
CVE-2025-38566HIGH7.5In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Sco...
CVE-2025-38565HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf/core: Exit early on perf_mmap() fail When per...
CVE-2025-38563HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf/core: Prevent VMA split of buffer mappings Th...
CVE-2025-38556HIGH7.1In the Linux kernel, the following vulnerability has been resolved: HID: core: Harden s32ton() against conversion to 0 ...
CVE-2025-38555HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_c...
CVE-2025-38554HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm: fix a UAF when vma->mm is freed after vma->vm_r...
CVE-2025-9146HIGH8.1A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file c...
CVE-2025-9140HIGH8.8A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this ...
CVE-2025-4046HIGH8.5A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges with...
CVE-2025-4044HIGH8.2Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to ...
CVE-2025-9136HIGH7.8A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the fil...
CVE-2025-41689HIGH7.5An unauthenticated remote attacker can get access without password protection to the affected device. This enables the u...
CVE-2025-7670HIGH7.5The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in...
CVE-2025-7654HIGH8.8Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes ...
CVE-2025-8218HIGH8.8The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the...
CVE-2025-54156HIGH7.5The Sante PACS Server Web Portal sends credential information without encryption.
CVE-2025-53948HIGH8.7The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a deni...
CVE-2025-52584HIGH8.4In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati...
CVE-2025-46269HIGH8.4In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati...
CVE-2025-53705HIGH8.4In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati...
CVE-2025-41392HIGH8.4In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati...
CVE-2025-8098HIGH8.5An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate pri...
CVE-2025-55588HIGH7.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/form...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now