2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40359——In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix KASAN global-out-of-bounds warn...
CVE-2025-40358HIGH7.1In the Linux kernel, the following vulnerability has been resolved: riscv: stacktrace: Disable KASAN checks for non-cur...
CVE-2025-40357——In the Linux kernel, the following vulnerability has been resolved: net/smc: fix general protection fault in __smc_diag...
CVE-2025-40356HIGH7.8In the Linux kernel, the following vulnerability has been resolved: spi: rockchip-sfc: Fix DMA-API usage Use DMA-API d...
CVE-2025-40355——In the Linux kernel, the following vulnerability has been resolved: sysfs: check visibility before changing group attri...
CVE-2025-40354HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: increase max link count and fix li...
CVE-2025-40353——In the Linux kernel, the following vulnerability has been resolved: arm64: mte: Do not warn if the page is already tagg...
CVE-2025-40352——In the Linux kernel, the following vulnerability has been resolved: platform/mellanox: mlxbf-pmc: add sysfs_attr_init()...
CVE-2025-40351——In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in hfsplus_de...
CVE-2025-40350CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix generating skb from non-linear x...
CVE-2025-40349HIGH7.8In the Linux kernel, the following vulnerability has been resolved: hfs: validate record offset in hfsplus_bmap_alloc ...
CVE-2025-40348——In the Linux kernel, the following vulnerability has been resolved: slab: Avoid race on slab->obj_exts in alloc_slab_ob...
CVE-2025-40347HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix the deadlock of enetc_mdio_lock Af...
CVE-2025-40346——In the Linux kernel, the following vulnerability has been resolved: arch_topology: Fix incorrect error check in topolog...
CVE-2025-65076MEDIUM6.1WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-65075MEDIUM6.5WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-65074HIGH7.2WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-14780MEDIUM6.3A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknow...
CVE-2025-14443MEDIUM6.4A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, ...
CVE-2025-13741MEDIUM4.3The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo...
CVE-2025-13474HIGH7.5Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation o...
CVE-2025-11220MEDIUM6.4The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all...
CVE-2025-0836MEDIUM6.3Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management S...
CVE-2025-14002HIGH8.1The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and ...
CVE-2025-68088MEDIUM5.4Missing Authorization vulnerability in merkulove Huger for Elementor huger-elementor allows Exploiting Incorrectly Confi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now