2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-38110HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net/mdiobus: Fix potential out-of-bounds clause 45 ...
CVE-2025-38109HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix ECVF vports unload on shutdown flow ...
CVE-2025-38108HIGH7In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in __red_change() Gerra...
CVE-2025-38107HIGH7In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: fix a race in ets_qdisc_change() G...
CVE-2025-38106HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring: fix use-after-free of sq->thread in __io_...
CVE-2025-38103HIGH7.1In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: Eliminate recurrent out-of-bounds bug ...
CVE-2025-38102HIGH7In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between vmci_host_setup_notify and v...
CVE-2025-38101HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix buffer locking in ring_buffer_subb...
CVE-2025-43025HIGH7.5HP Universal Print Driver is potentially vulnerable to denial of service due to buffer overflow in versions of UPD 7.4 o...
CVE-2025-34079HIGH7.8An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and Ex...
CVE-2025-34078HIGH7.8A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web interface and ExternalScripts...
CVE-2025-34076HIGH7.2An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the ba...
CVE-2025-49713HIGH8.8Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2025-52841HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This i...
CVE-2025-53110HIGH7.3Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio...
CVE-2025-53109HIGH7.3Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio...
CVE-2025-38091HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check stream id dml21 wrapper to g...
CVE-2025-53106HIGH8.8Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-...
CVE-2025-49588HIGH8.7Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve...
CVE-2025-34057HIGH8.7An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR...
CVE-2025-4946HIGH8.1The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in th...
CVE-2025-27025HIGH8.8The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is g...
CVE-2025-27021HIGH7.8The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low pri...
CVE-2025-24332HIGH7.1Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after perfo...
CVE-2025-6464HIGH8.8The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now