2025 CVE Vulnerabilities

45,212 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62509HIGH8.1FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version...
CVE-2025-55086CRITICAL9.8In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there ...
CVE-2025-47902HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Pro...
CVE-2025-47901HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti...
CVE-2025-47900HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti...
CVE-2025-3465HIGH8.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB C...
CVE-2025-11979MEDIUM6.5An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation...
CVE-2025-9574CRITICAL10Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects ...
CVE-2025-6515MEDIUM6.8The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographical...
CVE-2025-62429HIGH7.2ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbi...
CVE-2025-60856MEDIUM6.8Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attack...
CVE-2025-48025MEDIUM4.3In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000,...
CVE-2025-40017In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix memory leak by freeing untracked p...
CVE-2025-40016In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Mark invalid entities with id UVC_...
CVE-2025-40015In the Linux kernel, the following vulnerability has been resolved: media: stm32-csi: Fix dereference before NULL check...
CVE-2025-40013In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: audioreach: fix potential null pointer ...
CVE-2025-40012HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/smc: fix warning in smc_rx_splice() when callin...
CVE-2025-40011In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix null dereference in hdmi teardown ...
CVE-2025-40010In the Linux kernel, the following vulnerability has been resolved: afs: Fix potential null pointer dereference in afs_...
CVE-2025-40009In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: check p->vec_buf for NULL When t...
CVE-2025-40008In the Linux kernel, the following vulnerability has been resolved: kmsan: fix out-of-bounds access to shadow memory R...
CVE-2025-40007In the Linux kernel, the following vulnerability has been resolved: netfs: fix reference leak Commit 20d72b00ca81 ("ne...
CVE-2025-40006HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix folio is still mapped when deleted ...
CVE-2025-40005MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle ...
CVE-2025-26782HIGH7.5An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now