2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-21724HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iommufd/iova_bitmap: Fix shift-out-of-bounds in iov...
CVE-2025-21722HIGH7.8In the Linux kernel, the following vulnerability has been resolved: nilfs2: do not force clear folio if buffer is refer...
CVE-2025-21719HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ipmr: do not call mr_mfc_uses_dev() for unres entri...
CVE-2025-21718HIGH7In the Linux kernel, the following vulnerability has been resolved: net: rose: fix timer races against user threads Ro...
CVE-2025-21717HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: add missing cpu_to_node to kvzalloc_node...
CVE-2025-21715HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: davicom: fix UAF in dm9000_drv_remove dm is n...
CVE-2025-21714HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix implicit ODP use after free Prevent...
CVE-2025-20111HIGH7.4A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Swi...
CVE-2025-1634HIGH7.5A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are...
CVE-2025-25825HIGH7.1A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML...
CVE-2025-25823HIGH7.3A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML...
CVE-2025-22881HIGH7.8Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-...
CVE-2025-22869HIGH7.5SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which comp...
CVE-2025-22868HIGH7.5An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
CVE-2025-0889HIGH7.8Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows i...
CVE-2025-25515HIGH8.8Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the d...
CVE-2025-0514HIGH7.8Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targ...
CVE-2025-27148HIGH8.8Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like sys...
CVE-2025-27142HIGH8.8LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over the...
CVE-2025-27110HIGH7.5Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurit...
CVE-2025-23046HIGH7.5GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "M...
CVE-2025-1204HIGH7.7The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address...
CVE-2025-1068HIGH7.3There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged att...
CVE-2025-1067HIGH7.3There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker ...
CVE-2025-26601HIGH7.8A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now