2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62577HIGH8.8ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged ...
CVE-2025-40004In the Linux kernel, the following vulnerability has been resolved: net/9p: Fix buffer overflow in USB transport layer ...
CVE-2025-11948CRITICAL9.8Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthent...
CVE-2025-11947MEDIUM4.5A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the c...
CVE-2025-11946MEDIUM5.4A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process...
CVE-2025-11945LOW3.5A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the compo...
CVE-2025-11944HIGH7.2A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/control...
CVE-2025-11943CRITICAL9.8A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality ...
CVE-2025-11942CRITICAL9.8A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing ...
CVE-2025-11941HIGH8.1A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php...
CVE-2025-11940HIGH7.3A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of ...
CVE-2025-11939HIGH7.2A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/Chu...
CVE-2025-11938HIGH8.1A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/se...
CVE-2025-62672MEDIUM5.3rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecifie...
CVE-2025-47410HIGH8.8Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could all...
CVE-2025-11926MEDIUM4.4The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2025-9890HIGH8.8The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-5555HIGH7.8A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in th...
CVE-2025-40003In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix use-after-free caused by cyc...
CVE-2025-40002In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix use-after-free in tb_dp_dprx_work ...
CVE-2025-40001In the Linux kernel, the following vulnerability has been resolved: scsi: mvsas: Fix use-after-free bugs in mvs_work_qu...
CVE-2025-11256MEDIUM5.3The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2025-10750MEDIUM5.3The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, ...
CVE-2025-9562MEDIUM6.4The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs...
CVE-2025-11741MEDIUM5.3The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now