2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39822 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: fix signedness in this_len calculati... |
| CVE-2025-39820 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add a null ptr check for dpu_encoder_n... |
| CVE-2025-39819 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/smb: Fix inconsistent refcnt update A possible ... |
| CVE-2025-39816 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: always use READ_ONCE() to read ring ... |
| CVE-2025-39815 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: fix stack overrun when loading vlenb ... |
| CVE-2025-39814 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ice: fix NULL pointer dereference in ice_unplug_aux... |
| CVE-2025-39813 | MEDIUM | 4.7 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix potential warning in trace_printk_seq d... |
| CVE-2025-39812 | MEDIUM | 5.5 | 0.2% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: sctp: initialize more fields in sctp_v6_from_sk() ... |
| CVE-2025-39811 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Clear the scratch_pt pointer on error A... |
| CVE-2025-39808 | MEDIUM | 5.5 | 0.2% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: HID: hid-ntrig: fix unable to handle page fault in ... |
| CVE-2025-39807 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Add error handling for old state CRTC... |
| CVE-2025-39805 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: macb: fix unregister_netdev call order in macb... |
| CVE-2025-10546 | MEDIUM | 5.1 | 0.5% | Sep 16, 2025 | This vulnerability exist in PPC 2K15X Router, due to improper input validation for the Common Gateway Interface (CGI) pa... |
| CVE-2025-10536 | MEDIUM | 6.2 | 0.2% | Sep 16, 2025 | Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.... |
| CVE-2025-10532 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR ... |
| CVE-2025-10531 | MEDIUM | 5.4 | 0.3% | Sep 16, 2025 | Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbi... |
| CVE-2025-10530 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunder... |
| CVE-2025-10529 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thund... |
| CVE-2025-10290 | MEDIUM | 6.5 | 0.2% | Sep 16, 2025 | Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the ... |
| CVE-2025-8446 | MEDIUM | 4.3 | 0.2% | Sep 16, 2025 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capab... |
| CVE-2025-6575 | MEDIUM | 6.1 | 0.2% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dolusoft Om... |
| CVE-2025-56697 | MEDIUM | 6.1 | 0.3% | Sep 16, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks ... |
| CVE-2025-26711 | MEDIUM | 5.7 | 0.2% | Sep 16, 2025 | There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interfa... |
| CVE-2025-10015 | MEDIUM | 4.8 | 0.1% | Sep 16, 2025 | The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its ... |
| CVE-2025-2404 | MEDIUM | 4.3 | 0.2% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Inform... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now