2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22041 | HIGH | 8.8 | 0.6% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregis... |
| CVE-2025-22040 | HIGH | 8.8 | 0.6% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel c... |
| CVE-2025-22039 | HIGH | 7.1 | 0.3% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The... |
| CVE-2025-22038 | HIGH | 7.1 | 0.3% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is... |
| CVE-2025-22036 | HIGH | 7 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix random stack corruption after get_block ... |
| CVE-2025-22035 | HIGH | 7.8 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in print_graph_function... |
| CVE-2025-39592 | HIGH | 7.5 | 0.7% | Apr 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39584 | HIGH | 7.5 | 0.7% | Apr 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39570 | HIGH | 8.8 | 0.6% | Apr 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39566 | HIGH | 7.6 | 0.5% | Apr 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Hostel hostel ... |
| CVE-2025-39565 | HIGH | 7.2 | 0.7% | Apr 16, 2025 | Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Ob... |
| CVE-2025-39548 | HIGH | 7.1 | 0.2% | Apr 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban right-click-disable-or-ban allow... |
| CVE-2025-39547 | HIGH | 7.1 | 0.2% | Apr 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Sto... |
| CVE-2025-39544 | HIGH | 7.4 | 0.2% | Apr 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in sminozzi WP Tools wptools allows Path Traversal.This issue affects WP... |
| CVE-2025-39530 | HIGH | 7.1 | 0.2% | Apr 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in dsky Site Search 360 site-search-360 allows Stored XSS.This issue aff... |
| CVE-2025-39518 | HIGH | 7.6 | 0.5% | Apr 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedefiningTheWeb B... |
| CVE-2025-1982 | HIGH | 7.1 | 0.5% | Apr 16, 2025 | Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a lo... |
| CVE-2025-3685 | HIGH | 8.8 | 0.4% | Apr 16, 2025 | A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. Affected is... |
| CVE-2025-30960 | HIGH | 8.3 | 0.3% | Apr 16, 2025 | Missing Authorization vulnerability in fs-code FS Poster fs-poster.This issue affects FS Poster: from n/a through <= 6.5... |
| CVE-2025-22023 | HIGH | 7.8 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Don't skip on Stopped - Length Invalid ... |
| CVE-2025-22022 | HIGH | 7.8 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Apply the link chain quirk on NEC isoc e... |
| CVE-2025-22020 | HIGH | 7.8 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: memstick: rtsx_usb_ms: Fix slab-use-after-free in r... |
| CVE-2025-3698 | HIGH | 7.5 | 0.3% | Apr 16, 2025 | Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage ris... |
| CVE-2025-3663 | HIGH | 8.2 | 8.0% | Apr 16, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue a... |
| CVE-2025-30100 | HIGH | 7.8 | 0.1% | Apr 16, 2025 | Dell Alienware Command Center 6.x, versions prior to 6.7.37.0 contain an Improper Access Control Vulnerability. A low pr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now