2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38548 | HIGH | 7.8 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Validate the size of the rece... |
| CVE-2025-38538 | HIGH | 7.8 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: nbpfaxi: Fix memory corruption in probe(... |
| CVE-2025-38536 | HIGH | 7.8 | 0.1% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix potential use-after-free in airoha... |
| CVE-2025-38535 | HIGH | 7.8 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Fix unbalanced regulator disable ... |
| CVE-2025-38533 | HIGH | 7.8 | 0.1% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix the using of Rx buffer DMA The wx_... |
| CVE-2025-38530 | HIGH | 7.1 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: comedi: pcl812: Fix bit shift out of bounds When c... |
| CVE-2025-38529 | HIGH | 7.1 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: comedi: aio_iiro_16: Fix bit shift out of bounds W... |
| CVE-2025-38527 | HIGH | 7.8 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_brea... |
| CVE-2025-38521 | HIGH | 7.1 | 0.1% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix kernel crash when hard resetti... |
| CVE-2025-38512 | HIGH | 7.8 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: prevent A-MSDU attacks in mesh networks This... |
| CVE-2025-38502 | HIGH | 7.1 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial... |
| CVE-2025-38501 | HIGH | 7.5 | 2.1% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with... |
| CVE-2025-7664 | HIGH | 7.5 | 0.5% | Aug 16, 2025 | The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_act... |
| CVE-2025-6080 | HIGH | 8.8 | 0.3% | Aug 16, 2025 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in... |
| CVE-2025-6079 | HIGH | 8.8 | 0.5% | Aug 16, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f... |
| CVE-2025-3671 | HIGH | 8.8 | 0.7% | Aug 16, 2025 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u... |
| CVE-2025-55284 | HIGH | 7.5 | 0.4% | Aug 16, 2025 | Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prom... |
| CVE-2025-55286 | HIGH | 7.3 | 0.1% | Aug 16, 2025 | z2d is a pure Zig 2D graphics library. z2d v0.7.0 released with a new multi-sample anti-aliasing (MSAA) method, which us... |
| CVE-2025-52621 | HIGH | 7.5 | 0.1% | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning. The BigFix SaaS's HTTP responses were observe... |
| CVE-2025-8959 | HIGH | 7.5 | 0.5% | Aug 15, 2025 | HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized rea... |
| CVE-2025-43490 | HIGH | 8.4 | 0.1% | Aug 15, 2025 | A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support... |
| CVE-2025-8675 | HIGH | 8.8 | 0.2% | Aug 15, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This i... |
| CVE-2025-8361 | HIGH | 7.6 | 0.3% | Aug 15, 2025 | Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: f... |
| CVE-2025-8092 | HIGH | 7.6 | 0.3% | Aug 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con... |
| CVE-2025-49898 | HIGH | 7.6 | 0.4% | Aug 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now