2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40130In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix data race in CPU latency PM Qo...
CVE-2025-40129HIGH7.5In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix null pointer dereference on zero-length...
CVE-2025-40128Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-40127In the Linux kernel, the following vulnerability has been resolved: hwrng: ks-sa - fix division by zero in ks_sa_rng_in...
CVE-2025-40126In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr...
CVE-2025-40125In the Linux kernel, the following vulnerability has been resolved: blk-mq: check kobject state_in_sysfs before deletin...
CVE-2025-40124HIGH7.8In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr...
CVE-2025-40123HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce expected_attach_type for tailcall comp...
CVE-2025-40122In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: Fix IA32_PMC_x_CFG_B MSRs access er...
CVE-2025-40121In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: bytcr_rt5651: Fix invalid quirk input ...
CVE-2025-40120In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: hold PM usage ref to avoid PM/MDIO ...
CVE-2025-40119In the Linux kernel, the following vulnerability has been resolved: ext4: fix potential null deref in ext4_mb_init() I...
CVE-2025-40118HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Fix array-index-out-of-of-bounds on r...
CVE-2025-40117HIGH7.8In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Fix array underflow in pci...
CVE-2025-40116In the Linux kernel, the following vulnerability has been resolved: usb: host: max3421-hcd: Fix error pointer dereferen...
CVE-2025-40115In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix crash in transport port remove b...
CVE-2025-40113In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom: pas: Shutdown lite ADSP DTB on X1...
CVE-2025-40112HIGH7.8In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{fr...
CVE-2025-11994HIGH7.2The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter i...
CVE-2025-11454MEDIUM6.5The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable t...
CVE-2025-64407MEDIUM5.3Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att...
CVE-2025-61623MEDIUM6.5Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users ...
CVE-2025-59118HIGH7.3Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before ...
CVE-2025-37734MEDIUM4.3Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by t...
CVE-2025-12382HIGH8.8Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now