2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-38548HIGH7.8In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Validate the size of the rece...
CVE-2025-38538HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dmaengine: nbpfaxi: Fix memory corruption in probe(...
CVE-2025-38536HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix potential use-after-free in airoha...
CVE-2025-38535HIGH7.8In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Fix unbalanced regulator disable ...
CVE-2025-38533HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix the using of Rx buffer DMA The wx_...
CVE-2025-38530HIGH7.1In the Linux kernel, the following vulnerability has been resolved: comedi: pcl812: Fix bit shift out of bounds When c...
CVE-2025-38529HIGH7.1In the Linux kernel, the following vulnerability has been resolved: comedi: aio_iiro_16: Fix bit shift out of bounds W...
CVE-2025-38527HIGH7.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_brea...
CVE-2025-38521HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix kernel crash when hard resetti...
CVE-2025-38512HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: prevent A-MSDU attacks in mesh networks This...
CVE-2025-38502HIGH7.1In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial...
CVE-2025-38501HIGH7.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with...
CVE-2025-7664HIGH7.5The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_act...
CVE-2025-6080HIGH8.8The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in...
CVE-2025-6079HIGH8.8The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f...
CVE-2025-3671HIGH8.8The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u...
CVE-2025-55284HIGH7.5Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prom...
CVE-2025-55286HIGH7.3z2d is a pure Zig 2D graphics library. z2d v0.7.0 released with a new multi-sample anti-aliasing (MSAA) method, which us...
CVE-2025-52621HIGH7.5HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observe...
CVE-2025-8959HIGH7.5HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized rea...
CVE-2025-43490HIGH8.4A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support...
CVE-2025-8675HIGH8.8Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This i...
CVE-2025-8361HIGH7.6Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: f...
CVE-2025-8092HIGH7.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con...
CVE-2025-49898HIGH7.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now