2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34307 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34306 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34305 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain multiple stored cross-site scripting (XSS) vulnerabilities cause... |
| CVE-2025-34304 | MEDIUM | 6.5 | 0.4% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attac... |
| CVE-2025-34303 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34302 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34301 | MEDIUM | 5.4 | 5.0% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-53855 | HIGH | 7.8 | 0.3% | Oct 28, 2025 | An out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A spe... |
| CVE-2025-53814 | HIGH | 7.8 | 0.3% | Oct 28, 2025 | A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially... |
| CVE-2025-12390 | MEDIUM | 6 | 0.1% | Oct 28, 2025 | A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use... |
| CVE-2025-12380 | CRITICAL | 9.8 | 0.3% | Oct 28, 2025 | Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or bro... |
| CVE-2025-12103 | MEDIUM | 5 | 0.2% | Oct 28, 2025 | A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a... |
| CVE-2025-1038 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, al... |
| CVE-2025-1037 | HIGH | 7.5 | 0.1% | Oct 28, 2025 | By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user l... |
| CVE-2025-1036 | HIGH | 8.7 | 1.1% | Oct 28, 2025 | Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated us... |
| CVE-2025-9313 | CRITICAL | 9.3 | 0.5% | Oct 28, 2025 | An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants ful... |
| CVE-2025-40082 | HIGH | 7.1 | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni... |
| CVE-2025-40081 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: perf: arm_spe: Prevent overflow in PERF_IDX2OFF() ... |
| CVE-2025-40080 | — | — | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syz... |
| CVE-2025-40079 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Sign extend struct ops return values pr... |
| CVE-2025-40078 | — | — | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Explicitly check accesses to bpf_sock_addr Sy... |
| CVE-2025-40077 | — | — | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid overflow while left shift operat... |
| CVE-2025-40076 | — | — | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: PCI: rcar-host: Pass proper IRQ domain to generic_h... |
| CVE-2025-40075 | HIGH | 8.1 | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: use dst_dev_net_rcu() Replace three d... |
| CVE-2025-40074 | CRITICAL | 9.8 | 0.4% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrli... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now