2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40270 | HIGH | 7.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm, swap: fix potential UAF issue for VMA readahead... |
| CVE-2025-40269 | HIGH | 7.8 | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential overflow of PCM tran... |
| CVE-2025-40268 | — | — | 0.2% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: cifs: client: fix memory leak in smb3_fs_context_pa... |
| CVE-2025-40267 | — | — | 0.1% | Dec 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: ensure allocated iovec gets cleared fo... |
| CVE-2025-14141 | CRITICAL | 9.8 | 0.7% | Dec 6, 2025 | A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formA... |
| CVE-2025-14140 | MEDIUM | 6.5 | 0.5% | Dec 6, 2025 | A vulnerability was detected in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /gofor... |
| CVE-2025-14139 | MEDIUM | 5.7 | 1.0% | Dec 6, 2025 | A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Impacted is the function strcpy of the file /gof... |
| CVE-2025-14136 | HIGH | 8.8 | 1.0% | Dec 6, 2025 | A security flaw has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/... |
| CVE-2025-14135 | HIGH | 8.8 | 0.7% | Dec 6, 2025 | A vulnerability was identified in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0... |
| CVE-2025-14134 | HIGH | 8.8 | 0.7% | Dec 6, 2025 | A vulnerability was determined in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0... |
| CVE-2025-14133 | HIGH | 8.8 | 0.7% | Dec 6, 2025 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002... |
| CVE-2025-14126 | HIGH | 8.8 | 0.4% | Dec 6, 2025 | A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the c... |
| CVE-2025-13065 | HIGH | 8.8 | 7.1% | Dec 6, 2025 | The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, ... |
| CVE-2025-12966 | HIGH | 8.8 | 0.4% | Dec 6, 2025 | The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2025-12499 | HIGH | 7.2 | 0.3% | Dec 6, 2025 | The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the content... |
| CVE-2025-13748 | MEDIUM | 5.3 | 0.3% | Dec 6, 2025 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2025-13377 | HIGH | 8.1 | 0.5% | Dec 6, 2025 | The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbit... |
| CVE-2025-14117 | MEDIUM | 6.5 | 0.2% | Dec 6, 2025 | A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cro... |
| CVE-2025-13907 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The CSS3 Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode i... |
| CVE-2025-13899 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The TR Timthumb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versio... |
| CVE-2025-13898 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Ultra Skype Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_id' parameter of t... |
| CVE-2025-13896 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' paramet... |
| CVE-2025-13894 | MEDIUM | 6.1 | 0.2% | Dec 6, 2025 | The CSV Sumotto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` vari... |
| CVE-2025-13863 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The RevInsite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `token` parameter in all version... |
| CVE-2025-13857 | MEDIUM | 6.4 | 0.2% | Dec 6, 2025 | The Yet Another WebClap for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now