2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-39822MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: fix signedness in this_len calculati...
CVE-2025-39820MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add a null ptr check for dpu_encoder_n...
CVE-2025-39819MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/smb: Fix inconsistent refcnt update A possible ...
CVE-2025-39816MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: always use READ_ONCE() to read ring ...
CVE-2025-39815MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: fix stack overrun when loading vlenb ...
CVE-2025-39814MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ice: fix NULL pointer dereference in ice_unplug_aux...
CVE-2025-39813MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix potential warning in trace_printk_seq d...
CVE-2025-39812MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sctp: initialize more fields in sctp_v6_from_sk() ...
CVE-2025-39811MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Clear the scratch_pt pointer on error A...
CVE-2025-39808MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: HID: hid-ntrig: fix unable to handle page fault in ...
CVE-2025-39807MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Add error handling for old state CRTC...
CVE-2025-39805MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: macb: fix unregister_netdev call order in macb...
CVE-2025-10546MEDIUM5.1This vulnerability exist in PPC 2K15X Router, due to improper input validation for the Common Gateway Interface (CGI) pa...
CVE-2025-10536MEDIUM6.2Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140....
CVE-2025-10532MEDIUM6.5Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR ...
CVE-2025-10531MEDIUM5.4Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbi...
CVE-2025-10530MEDIUM6.5Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunder...
CVE-2025-10529MEDIUM6.5Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thund...
CVE-2025-10290MEDIUM6.5Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the ...
CVE-2025-8446MEDIUM4.3The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capab...
CVE-2025-6575MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dolusoft Om...
CVE-2025-56697MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks ...
CVE-2025-26711MEDIUM5.7There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interfa...
CVE-2025-10015MEDIUM4.8The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its ...
CVE-2025-2404MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Inform...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now