2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40191 | — | — | 0.1% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix kfd process ref leaking when userpt... |
| CVE-2025-40190 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in ... |
| CVE-2025-40189 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: Fix lost EEPROM read timeout err... |
| CVE-2025-40188 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: pwm: berlin: Fix wrong register in suspend/resume ... |
| CVE-2025-40187 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_dispositio... |
| CVE-2025-40186 | HIGH | 8.1 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn... |
| CVE-2025-40185 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ice: ice_adapter: release xa entry on adapter alloc... |
| CVE-2025-40184 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix debug checking for np-guests using ... |
| CVE-2025-40183 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4... |
| CVE-2025-40182 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: skcipher - Fix reqsize handling Commit afd... |
| CVE-2025-40181 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/kvm: Force legacy PCI hole to UC when overridin... |
| CVE-2025-40180 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: mailbox: zynqmp-ipi: Fix out-of-bounds access in ma... |
| CVE-2025-40179 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: verify orphan file size is not too big In pr... |
| CVE-2025-40178 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: pid: Add a judgment for ns null in pid_nr_ns __tas... |
| CVE-2025-33119 | MEDIUM | 6.5 | 0.2% | Nov 12, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be rea... |
| CVE-2025-64186 | MEDIUM | 6.5 | 0.1% | Nov 12, 2025 | Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verific... |
| CVE-2025-64170 | LOW | 3.8 | 0.1% | Nov 12, 2025 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0... |
| CVE-2025-63396 | LOW | 3.3 | 0.1% | Nov 12, 2025 | An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (Python... |
| CVE-2025-46608 | HIGH | 7.2 | 0.4% | Nov 12, 2025 | Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged a... |
| CVE-2025-36223 | MEDIUM | 6.1 | 0.1% | Nov 12, 2025 | IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST hea... |
| CVE-2025-13063 | HIGH | 7.3 | 0.3% | Nov 12, 2025 | A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead... |
| CVE-2025-13061 | HIGH | 8.8 | 0.3% | Nov 12, 2025 | A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /ind... |
| CVE-2025-8485 | HIGH | 7.3 | 0.1% | Nov 12, 2025 | An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to ex... |
| CVE-2025-8421 | MEDIUM | 6.6 | 0.1% | Nov 12, 2025 | An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during i... |
| CVE-2025-64117 | MEDIUM | 4.6 | 0.1% | Nov 12, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Editio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now