2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40270HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm, swap: fix potential UAF issue for VMA readahead...
CVE-2025-40269HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential overflow of PCM tran...
CVE-2025-40268In the Linux kernel, the following vulnerability has been resolved: cifs: client: fix memory leak in smb3_fs_context_pa...
CVE-2025-40267In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: ensure allocated iovec gets cleared fo...
CVE-2025-14141CRITICAL9.8A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formA...
CVE-2025-14140MEDIUM6.5A vulnerability was detected in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /gofor...
CVE-2025-14139MEDIUM5.7A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Impacted is the function strcpy of the file /gof...
CVE-2025-14136HIGH8.8A security flaw has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/...
CVE-2025-14135HIGH8.8A vulnerability was identified in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-14134HIGH8.8A vulnerability was determined in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-14133HIGH8.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-14126HIGH8.8A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the c...
CVE-2025-13065HIGH8.8The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, ...
CVE-2025-12966HIGH8.8The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2025-12499HIGH7.2The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the content...
CVE-2025-13748MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2025-13377HIGH8.1The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to arbit...
CVE-2025-14117MEDIUM6.5A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cro...
CVE-2025-13907MEDIUM6.4The CSS3 Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode i...
CVE-2025-13899MEDIUM6.4The TR Timthumb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versio...
CVE-2025-13898MEDIUM6.4The Ultra Skype Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_id' parameter of t...
CVE-2025-13896MEDIUM6.4The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' paramet...
CVE-2025-13894MEDIUM6.1The CSV Sumotto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` vari...
CVE-2025-13863MEDIUM6.4The RevInsite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `token` parameter in all version...
CVE-2025-13857MEDIUM6.4The Yet Another WebClap for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now