2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34307MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34306MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34305MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain multiple stored cross-site scripting (XSS) vulnerabilities cause...
CVE-2025-34304MEDIUM6.5IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attac...
CVE-2025-34303MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34302MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34301MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-53855HIGH7.8An out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A spe...
CVE-2025-53814HIGH7.8A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially...
CVE-2025-12390MEDIUM6A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use...
CVE-2025-12380CRITICAL9.8Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or bro...
CVE-2025-12103MEDIUM5A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a...
CVE-2025-1038HIGH7.5The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, al...
CVE-2025-1037HIGH7.5By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user l...
CVE-2025-1036HIGH8.7Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated us...
CVE-2025-9313CRITICAL9.3An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants ful...
CVE-2025-40082HIGH7.1In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni...
CVE-2025-40081HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf: arm_spe: Prevent overflow in PERF_IDX2OFF() ...
CVE-2025-40080In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syz...
CVE-2025-40079HIGH7.8In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Sign extend struct ops return values pr...
CVE-2025-40078In the Linux kernel, the following vulnerability has been resolved: bpf: Explicitly check accesses to bpf_sock_addr Sy...
CVE-2025-40077In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid overflow while left shift operat...
CVE-2025-40076In the Linux kernel, the following vulnerability has been resolved: PCI: rcar-host: Pass proper IRQ domain to generic_h...
CVE-2025-40075HIGH8.1In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: use dst_dev_net_rcu() Replace three d...
CVE-2025-40074CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrli...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now