2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21724 | HIGH | 7.8 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommufd/iova_bitmap: Fix shift-out-of-bounds in iov... |
| CVE-2025-21722 | HIGH | 7.8 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: do not force clear folio if buffer is refer... |
| CVE-2025-21719 | HIGH | 7.1 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipmr: do not call mr_mfc_uses_dev() for unres entri... |
| CVE-2025-21718 | HIGH | 7 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: rose: fix timer races against user threads Ro... |
| CVE-2025-21717 | HIGH | 7.1 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: add missing cpu_to_node to kvzalloc_node... |
| CVE-2025-21715 | HIGH | 7.8 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: davicom: fix UAF in dm9000_drv_remove dm is n... |
| CVE-2025-21714 | HIGH | 7.8 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix implicit ODP use after free Prevent... |
| CVE-2025-20111 | HIGH | 7.4 | 0.3% | Feb 26, 2025 | A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Swi... |
| CVE-2025-1634 | HIGH | 7.5 | 0.8% | Feb 26, 2025 | A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are... |
| CVE-2025-25825 | HIGH | 7.1 | 0.2% | Feb 26, 2025 | A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML... |
| CVE-2025-25823 | HIGH | 7.3 | 0.2% | Feb 26, 2025 | A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML... |
| CVE-2025-22881 | HIGH | 7.8 | 0.3% | Feb 26, 2025 | Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-... |
| CVE-2025-22869 | HIGH | 7.5 | 0.9% | Feb 26, 2025 | SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which comp... |
| CVE-2025-22868 | HIGH | 7.5 | 0.8% | Feb 26, 2025 | An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing. |
| CVE-2025-0889 | HIGH | 7.8 | 0.2% | Feb 26, 2025 | Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows i... |
| CVE-2025-25515 | HIGH | 8.8 | 0.5% | Feb 25, 2025 | Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the d... |
| CVE-2025-0514 | HIGH | 7.8 | 0.3% | Feb 25, 2025 | Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targ... |
| CVE-2025-27148 | HIGH | 8.8 | 0.2% | Feb 25, 2025 | Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like sys... |
| CVE-2025-27142 | HIGH | 8.8 | 0.5% | Feb 25, 2025 | LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over the... |
| CVE-2025-27110 | HIGH | 7.5 | 0.4% | Feb 25, 2025 | Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurit... |
| CVE-2025-23046 | HIGH | 7.5 | 0.4% | Feb 25, 2025 | GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "M... |
| CVE-2025-1204 | HIGH | 7.7 | 0.4% | Feb 25, 2025 | The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address... |
| CVE-2025-1068 | HIGH | 7.3 | 0.2% | Feb 25, 2025 | There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged att... |
| CVE-2025-1067 | HIGH | 7.3 | 0.2% | Feb 25, 2025 | There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker ... |
| CVE-2025-26601 | HIGH | 7.8 | 0.4% | Feb 25, 2025 | A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now