2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53883 | CRITICAL | 9.3 | 0.3% | Oct 30, 2025 | A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run ar... |
| CVE-2025-53880 | HIGH | 8.7 | 0.3% | Oct 30, 2025 | A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent n... |
| CVE-2025-39663 | HIGH | 8.4 | 0.5% | Oct 30, 2025 | Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject ... |
| CVE-2025-62503 | MEDIUM | 4.6 | 0.4% | Oct 30, 2025 | User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create... |
| CVE-2025-62402 | MEDIUM | 5.4 | 0.5% | Oct 30, 2025 | API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server w... |
| CVE-2025-54941 | MEDIUM | 4.6 | 0.4% | Oct 30, 2025 | An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a... |
| CVE-2025-54471 | MEDIUM | 6.5 | 0.2% | Oct 30, 2025 | NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was repla... |
| CVE-2025-54470 | HIGH | 8.6 | 0.2% | Oct 30, 2025 | This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When thi... |
| CVE-2025-54469 | CRITICAL | 9.9 | 0.4% | Oct 30, 2025 | A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_... |
| CVE-2025-40105 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: vfs: Don't leak disconnected dentries on umount Wh... |
| CVE-2025-40104 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix mailbox API compatibility by negotiati... |
| CVE-2025-40103 | — | — | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix refcount leak for cifs_sb_tlink F... |
| CVE-2025-40102 | — | — | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Prevent access to vCPU events before in... |
| CVE-2025-40101 | — | — | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leaks when rejecting a non SINGLE... |
| CVE-2025-40100 | — | — | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not assert we found block group item when... |
| CVE-2025-40099 | CRITICAL | 9.4 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed... |
| CVE-2025-40098 | — | — | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l41: Fix NULL pointer dereference in... |
| CVE-2025-40097 | — | — | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix missing pointer check in hda_compone... |
| CVE-2025-40096 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix potential double free in drm_sched_j... |
| CVE-2025-40095 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_rndis: Refactor bind path to use __f... |
| CVE-2025-40094 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_acm: Refactor bind path to use __fre... |
| CVE-2025-40093 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ecm: Refactor bind path to use __fre... |
| CVE-2025-40092 | HIGH | 7.8 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Refactor bind path to use __fre... |
| CVE-2025-40091 | — | — | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix too early devlink_free() in ixgbe_remove... |
| CVE-2025-40090 | MEDIUM | 5.5 | 0.1% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list acc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now