2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-40364HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffe...
CVE-2025-3786HIGH8.8A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fr...
CVE-2025-3785HIGH8.8A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown ...
CVE-2025-40114HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iio: light: Add check for array bounds in veml6075_...
CVE-2025-40014HIGH7.8In the Linux kernel, the following vulnerability has been resolved: objtool, spi: amd: Fix out-of-bounds stack access i...
CVE-2025-39778HIGH7.1In the Linux kernel, the following vulnerability has been resolved: objtool, nvmet: Fix out-of-bounds stack access in n...
CVE-2025-39735HIGH7.1In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() Durin...
CVE-2025-38479HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: free irq correctly in remove p...
CVE-2025-37785HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounti...
CVE-2025-39470HIGH8.1Path Traversal: '.../...//' vulnerability in ThimPress Ivy School ivy-school allows PHP Local File Inclusion.This issue ...
CVE-2025-39469HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pantherius Modal S...
CVE-2025-3520HIGH8.1The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a f...
CVE-2025-0467HIGH8.2Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou...
CVE-2025-3509HIGH7.2A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute...
CVE-2025-3246HIGH7.6An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scr...
CVE-2025-29461HIGH7.6An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ p...
CVE-2025-29460HIGH7.6An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the ...
CVE-2025-29459HIGH7.6An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Suppli...
CVE-2025-29458HIGH7.6An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: t...
CVE-2025-29457HIGH7.6An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: ...
CVE-2025-29452HIGH7.6An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
CVE-2025-29451HIGH7.6An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
CVE-2025-3765HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen...
CVE-2025-3764HIGH8.8A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Thi...
CVE-2025-3763HIGH7.8A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the fu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now