2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40089In the Linux kernel, the following vulnerability has been resolved: cxl/features: Add check for no entries in cxl_featu...
CVE-2025-40088HIGH7.1In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_str...
CVE-2025-40087HIGH7.5In the Linux kernel, the following vulnerability has been resolved: NFSD: Define a proc_layoutcommit for the FlexFiles ...
CVE-2025-40086In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't allow evicting of BOs in same VM in a...
CVE-2025-11906MEDIUM6.7A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect...
CVE-2025-11881MEDIUM5.3The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
CVE-2025-62230HIGH7.3A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The soft...
CVE-2025-62229HIGH7.3A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error ...
CVE-2025-11627MEDIUM6.5The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log ...
CVE-2025-10636LOW3.5The NS Maintenance Mode for WP WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which c...
CVE-2025-10008MEDIUM5.3The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due...
CVE-2025-62231HIGH7.3A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCom...
CVE-2025-12475MEDIUM6.4The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsle...
CVE-2025-9954HIGH7.5Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0....
CVE-2025-62257MEDIUM5.3Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Lifera...
CVE-2025-12466HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect ...
CVE-2025-12083MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme ...
CVE-2025-12082HIGH7.5Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects Civ...
CVE-2025-10931LOW3.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analy...
CVE-2025-10930MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects ...
CVE-2025-10929MEDIUM5.3Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Co...
CVE-2025-10928MEDIUM6.3Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This is...
CVE-2025-10927MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible t...
CVE-2025-10926MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field ...
CVE-2025-61725HIGH7.5The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now