2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-2158HIGH8.8The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L...
CVE-2025-4497HIGH7.8A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue af...
CVE-2025-1137HIGH8.8IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privil...
CVE-2025-47424HIGH7.1Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, ...
CVE-2025-4447HIGH7.8In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by m...
CVE-2025-47269HIGH8.3code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted ...
CVE-2025-4480HIGH7.8A vulnerability was found in code-projects Simple College Management System 1.0. It has been declared as critical. This ...
CVE-2025-29509HIGH8.8Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conve...
CVE-2025-1278HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 1...
CVE-2025-28203HIGH8.8Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
CVE-2025-28202HIGH8.8Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services witho...
CVE-2025-4206HIGH7.2The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulner...
CVE-2025-3528HIGH8.2A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has...
CVE-2025-4472HIGH7.8A vulnerability was found in code-projects Departmental Store Management System 1.0. It has been classified as critical....
CVE-2025-4471HIGH7.8A vulnerability, which was classified as critical, has been found in code-projects Jewelery Store Management system 1.0....
CVE-2025-3455HIGH8.8The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized...
CVE-2025-37885HIGH7.8In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reset IRTE to host control if *new* route...
CVE-2025-37882HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix isochronous Ring Underrun/Overrun ev...
CVE-2025-37879HIGH7.1In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative rea...
CVE-2025-37869HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe: Use local fence in error path of xe_migrate...
CVE-2025-37861HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Synchronous access b/w reset and tm t...
CVE-2025-37854HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix mode1 reset crash issue If HW sche...
CVE-2025-37849HIGH7.8In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation ...
CVE-2025-37846HIGH7.1In the Linux kernel, the following vulnerability has been resolved: arm64: mops: Do not dereference src reg for a set o...
CVE-2025-37845HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tracing: fprobe events: Fix possible UAF on modules...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now