2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40089 | — | — | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Add check for no entries in cxl_featu... |
| CVE-2025-40088 | HIGH | 7.1 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_str... |
| CVE-2025-40087 | HIGH | 7.5 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Define a proc_layoutcommit for the FlexFiles ... |
| CVE-2025-40086 | — | — | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't allow evicting of BOs in same VM in a... |
| CVE-2025-11906 | MEDIUM | 6.7 | 0.1% | Oct 30, 2025 | A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect... |
| CVE-2025-11881 | MEDIUM | 5.3 | 0.3% | Oct 30, 2025 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing... |
| CVE-2025-62230 | HIGH | 7.3 | 0.3% | Oct 30, 2025 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The soft... |
| CVE-2025-62229 | HIGH | 7.3 | 0.5% | Oct 30, 2025 | A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension notifications. Improper error ... |
| CVE-2025-11627 | MEDIUM | 6.5 | 0.3% | Oct 30, 2025 | The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log ... |
| CVE-2025-10636 | LOW | 3.5 | 0.2% | Oct 30, 2025 | The NS Maintenance Mode for WP WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which c... |
| CVE-2025-10008 | MEDIUM | 5.3 | 0.3% | Oct 30, 2025 | The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due... |
| CVE-2025-62231 | HIGH | 7.3 | 0.3% | Oct 30, 2025 | A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCom... |
| CVE-2025-12475 | MEDIUM | 6.4 | 0.2% | Oct 30, 2025 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsle... |
| CVE-2025-9954 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.... |
| CVE-2025-62257 | MEDIUM | 5.3 | 0.4% | Oct 30, 2025 | Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Lifera... |
| CVE-2025-12466 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect ... |
| CVE-2025-12083 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme ... |
| CVE-2025-12082 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects Civ... |
| CVE-2025-10931 | LOW | 3.8 | 0.2% | Oct 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analy... |
| CVE-2025-10930 | MEDIUM | 4.3 | 0.1% | Oct 30, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects ... |
| CVE-2025-10929 | MEDIUM | 5.3 | 0.3% | Oct 30, 2025 | Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Co... |
| CVE-2025-10928 | MEDIUM | 6.3 | 0.2% | Oct 30, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This is... |
| CVE-2025-10927 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible t... |
| CVE-2025-10926 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field ... |
| CVE-2025-61725 | HIGH | 7.5 | 0.6% | Oct 29, 2025 | The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now