2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-38206HIGH7.8In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double ...
CVE-2025-38204HIGH7.1In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds read in add_miss...
CVE-2025-38201HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: clamp maximum map bucket...
CVE-2025-38198HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fbcon: Make sure modelist not set on unregistered c...
CVE-2025-38187HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_p...
CVE-2025-38183HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: lan743x: fix potential out-of-bounds write in ...
CVE-2025-38182HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ublk: santizize the arguments from userspace when a...
CVE-2025-38180HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: atm: fix /proc/net/atm/lec handling /proc/net...
CVE-2025-38179HIGH7.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix max_sge overflow in smb_extract_fo...
CVE-2025-49809HIGH7.8mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environm...
CVE-2025-52828HIGH8.8Deserialization of Untrusted Data vulnerability in designthemes Red Art redart allows Object Injection.This issue affect...
CVE-2025-52813HIGH8.1Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security ...
CVE-2025-52807HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-52805HIGH7.5Path Traversal: '.../...//' vulnerability in VaultDweller Leyka leyka allows PHP Local File Inclusion.This issue affects...
CVE-2025-52798HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch w...
CVE-2025-52796HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tggfref WP-Recall ...
CVE-2025-52776HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video...
CVE-2025-52718HIGH7.2Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code I...
CVE-2025-4414HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49870HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Me...
CVE-2025-49866HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikel Beautiful Co...
CVE-2025-49418HIGH7.2Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allmart-core allows Server Side Request Forgery...
CVE-2025-49274HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awordpresslife Neo...
CVE-2025-49247HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Team Show...
CVE-2025-49245HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Testimoni...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now