2025 CVE Vulnerabilities

45,185 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-37749HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net: ppp: Add bound checking for skb data on ppp_sy...
CVE-2025-37739HIGH7.1In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-bounds access in f2fs_tru...
CVE-2025-37738HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: ignore xattrs past end Once inside 'ext4_xat...
CVE-2025-23158HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add check to handle incorrect qu...
CVE-2025-23157HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: add check to avoid out of...
CVE-2025-23156HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: refactor hfi packet parsi...
CVE-2025-23142HIGH7.8In the Linux kernel, the following vulnerability has been resolved: sctp: detect and prevent references to a freed tran...
CVE-2025-4157HIGH8.8A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unkn...
CVE-2025-4156HIGH8.8A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe...
CVE-2025-4155HIGH8.8A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unkn...
CVE-2025-4154HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affect...
CVE-2025-3952HIGH8.1The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data t...
CVE-2025-1305HIGH8.8The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0....
CVE-2025-1304HIGH8.8The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the new...
CVE-2025-2816HIGH8.1The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of...
CVE-2025-4139HIGH8.8A vulnerability classified as critical was found in Netgear EX6120 1.0.0.68. Affected by this vulnerability is the funct...
CVE-2025-2082HIGH7.5Tesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent att...
CVE-2025-27611HIGH8.7base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0,...
CVE-2025-32777HIGH8.2Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology...
CVE-2025-2170HIGH7.2A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, wh...
CVE-2025-46619HIGH7.6A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that ...
CVE-2025-44194HIGH7.3SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?p...
CVE-2025-44193HIGH7.6SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?p...
CVE-2025-39413HIGH8.8Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This...
CVE-2025-33074HIGH8.8Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now