2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40130 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix data race in CPU latency PM Qo... |
| CVE-2025-40129 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix null pointer dereference on zero-length... |
| CVE-2025-40128 | — | — | — | Nov 12, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-40127 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: hwrng: ks-sa - fix division by zero in ks_sa_rng_in... |
| CVE-2025-40126 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr... |
| CVE-2025-40125 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: blk-mq: check kobject state_in_sysfs before deletin... |
| CVE-2025-40124 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr... |
| CVE-2025-40123 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce expected_attach_type for tailcall comp... |
| CVE-2025-40122 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix IA32_PMC_x_CFG_B MSRs access er... |
| CVE-2025-40121 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: bytcr_rt5651: Fix invalid quirk input ... |
| CVE-2025-40120 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: hold PM usage ref to avoid PM/MDIO ... |
| CVE-2025-40119 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix potential null deref in ext4_mb_init() I... |
| CVE-2025-40118 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Fix array-index-out-of-of-bounds on r... |
| CVE-2025-40117 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Fix array underflow in pci... |
| CVE-2025-40116 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421-hcd: Fix error pointer dereferen... |
| CVE-2025-40115 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix crash in transport port remove b... |
| CVE-2025-40113 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom: pas: Shutdown lite ADSP DTB on X1... |
| CVE-2025-40112 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr... |
| CVE-2025-11994 | HIGH | 7.2 | 0.3% | Nov 12, 2025 | The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter i... |
| CVE-2025-11454 | MEDIUM | 6.5 | 0.3% | Nov 12, 2025 | The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable t... |
| CVE-2025-64407 | MEDIUM | 5.3 | 0.4% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-61623 | MEDIUM | 6.5 | 0.7% | Nov 12, 2025 | Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users ... |
| CVE-2025-59118 | HIGH | 7.3 | 1.6% | Nov 12, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before ... |
| CVE-2025-37734 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by t... |
| CVE-2025-12382 | HIGH | 8.8 | 0.5% | Nov 12, 2025 | Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now