2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53883CRITICAL9.3A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run ar...
CVE-2025-53880HIGH8.7A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent n...
CVE-2025-39663HIGH8.4Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject ...
CVE-2025-62503MEDIUM4.6User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create...
CVE-2025-62402MEDIUM5.4API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server w...
CVE-2025-54941MEDIUM4.6An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a...
CVE-2025-54471MEDIUM6.5NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was repla...
CVE-2025-54470HIGH8.6This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When thi...
CVE-2025-54469CRITICAL9.9A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_...
CVE-2025-40105HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vfs: Don't leak disconnected dentries on umount Wh...
CVE-2025-40104HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix mailbox API compatibility by negotiati...
CVE-2025-40103In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix refcount leak for cifs_sb_tlink F...
CVE-2025-40102In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Prevent access to vCPU events before in...
CVE-2025-40101In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leaks when rejecting a non SINGLE...
CVE-2025-40100In the Linux kernel, the following vulnerability has been resolved: btrfs: do not assert we found block group item when...
CVE-2025-40099CRITICAL9.4In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed...
CVE-2025-40098In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in...
CVE-2025-40097In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix missing pointer check in hda_compone...
CVE-2025-40096HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix potential double free in drm_sched_j...
CVE-2025-40095HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Refactor bind path to use __f...
CVE-2025-40094HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_acm: Refactor bind path to use __fre...
CVE-2025-40093HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ecm: Refactor bind path to use __fre...
CVE-2025-40092HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Refactor bind path to use __fre...
CVE-2025-40091In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix too early devlink_free() in ixgbe_remove...
CVE-2025-40090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list acc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now