2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-22041HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregis...
CVE-2025-22040HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel c...
CVE-2025-22039HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The...
CVE-2025-22038HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is...
CVE-2025-22036HIGH7In the Linux kernel, the following vulnerability has been resolved: exfat: fix random stack corruption after get_block ...
CVE-2025-22035HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in print_graph_function...
CVE-2025-39592HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39584HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39570HIGH8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-39566HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Hostel hostel ...
CVE-2025-39565HIGH7.2Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Ob...
CVE-2025-39548HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban right-click-disable-or-ban allow...
CVE-2025-39547HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Sto...
CVE-2025-39544HIGH7.4Cross-Site Request Forgery (CSRF) vulnerability in sminozzi WP Tools wptools allows Path Traversal.This issue affects WP...
CVE-2025-39530HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in dsky Site Search 360 site-search-360 allows Stored XSS.This issue aff...
CVE-2025-39518HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedefiningTheWeb B...
CVE-2025-1982HIGH7.1Local File Inclusion vulnerability in Ready's attachment upload panel allows low privileged user to provide link to a lo...
CVE-2025-3685HIGH8.8A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. Affected is...
CVE-2025-30960HIGH8.3Missing Authorization vulnerability in fs-code FS Poster fs-poster.This issue affects FS Poster: from n/a through <= 6.5...
CVE-2025-22023HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Don't skip on Stopped - Length Invalid ...
CVE-2025-22022HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Apply the link chain quirk on NEC isoc e...
CVE-2025-22020HIGH7.8In the Linux kernel, the following vulnerability has been resolved: memstick: rtsx_usb_ms: Fix slab-use-after-free in r...
CVE-2025-3698HIGH7.5Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage ris...
CVE-2025-3663HIGH8.2A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue a...
CVE-2025-30100HIGH7.8Dell Alienware Command Center 6.x, versions prior to 6.7.37.0 contain an Improper Access Control Vulnerability. A low pr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now