2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10041CRITICAL9.8The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-10038MEDIUM6.5The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and includ...
CVE-2025-61941HIGH8.6A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered b...
CVE-2025-55039MEDIUM6.5This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 an...
CVE-2025-40000HIGH8.8In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix use-after-free in rtw89_core_tx_ki...
CVE-2025-39999In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix blk_mq_tags double free while nr_reques...
CVE-2025-39998HIGH7.1In the Linux kernel, the following vulnerability has been resolved: scsi: target: target_core_configfs: Add length chec...
CVE-2025-39997In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_u...
CVE-2025-39996In the Linux kernel, the following vulnerability has been resolved: media: b2c2: Fix use-after-free causing by irq_chec...
CVE-2025-39995In the Linux kernel, the following vulnerability has been resolved: media: i2c: tc358743: Fix use-after-free bugs cause...
CVE-2025-39994HIGH7.3In the Linux kernel, the following vulnerability has been resolved: media: tuner: xc5000: Fix use-after-free in xc5000_...
CVE-2025-39993HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot...
CVE-2025-39992In the Linux kernel, the following vulnerability has been resolved: mm: swap: check for stable address space before ope...
CVE-2025-39991In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3...
CVE-2025-39990HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Check the helper function is valid in get_help...
CVE-2025-39988HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: populate ndo_change_mtu() to preve...
CVE-2025-39987HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: hi311x: populate ndo_change_mtu() to prevent b...
CVE-2025-39986HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: sun4i_can: populate ndo_change_mtu() to preven...
CVE-2025-39985HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: mcba_usb: populate ndo_change_mtu() to prevent...
CVE-2025-39984In the Linux kernel, the following vulnerability has been resolved: net: tun: Update napi->skb after XDP process The s...
CVE-2025-39983HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_conn_tx_dequeu...
CVE-2025-39982HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix UAF in hci_acl_create_con...
CVE-2025-39981HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix possible UAFs This attemps to...
CVE-2025-39980In the Linux kernel, the following vulnerability has been resolved: nexthop: Forbid FDB status change while nexthop is ...
CVE-2025-39979HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, fix UAF in flow counter release Fix ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now