2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71286MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Correct the allocation si...
CVE-2025-71285MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Drop the MHI auto_queue feature for IPCR...
CVE-2025-71274MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: rpmsg: core: fix race in driver_override_show() and...
CVE-2025-71273MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Use devm_kmemdup() in rtw_set_supporte...
CVE-2025-71272MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: most: core: fix resource leak in most_register_inte...
CVE-2025-71271MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hfsplus: ensure sb->s_fs_info is always cleaned up ...
CVE-2025-62345LOW2.7HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component con...
CVE-2025-31951HIGH8.8HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a...
CVE-2025-59854MEDIUM6.1HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes t...
CVE-2025-59853MEDIUM5.3HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack tr...
CVE-2025-59852CRITICAL9.1HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted ove...
CVE-2025-59851CRITICAL9.8HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatc...
CVE-2025-31970MEDIUM6.1HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Polic...
CVE-2025-71256HIGH7.5In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no addition...
CVE-2025-71255HIGH7.5In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio...
CVE-2025-71254HIGH7.5In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio...
CVE-2025-71253HIGH7.5In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio...
CVE-2025-71252HIGH7.5In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio...
CVE-2025-71251HIGH7.5In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service w...
CVE-2025-66369HIGH7.5An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 128...
CVE-2025-61669MEDIUM6.1Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query pa...
CVE-2025-52206MEDIUM4.7ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
CVE-2025-42611MEDIUM6.5RouterOS provides various services that rely on correct verification of client and server certificates to secure confide...
CVE-2025-13618CRITICAL9.8The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. Th...
CVE-2025-67796HIGH8.1IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now