2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39978 | HIGH | 7.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix potential use after free in otx2_... |
| CVE-2025-39977 | HIGH | 7.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI sy... |
| CVE-2025-39976 | HIGH | 7.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: futex: Use correct exit on failure from futex_hash_... |
| CVE-2025-39975 | CRITICAL | 9.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix wrong index reference in smb2_comp... |
| CVE-2025-39974 | — | — | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix slab-out-of-bounds in _parse_i... |
| CVE-2025-39973 | HIGH | 8.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_... |
| CVE-2025-39972 | HIGH | 8.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in i40e_validate_queue_map... |
| CVE-2025-39971 | HIGH | 8.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in config queues msg Ensu... |
| CVE-2025-39970 | HIGH | 8.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: i40e: fix input validation logic for action_meta F... |
| CVE-2025-39969 | HIGH | 8.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: i40e: fix validation of VF state in get resources ... |
| CVE-2025-39968 | HIGH | 7.3 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: i40e: add max boundary check for VF filters There ... |
| CVE-2025-39967 | HIGH | 7.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: fbcon: fix integer overflow in fbcon_do_set_font F... |
| CVE-2025-39966 | HIGH | 7 | 0.1% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix race during abort for file descriptors... |
| CVE-2025-11501 | HIGH | 7.5 | 0.4% | Oct 15, 2025 | The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all v... |
| CVE-2025-11161 | MEDIUM | 5.4 | 0.2% | Oct 15, 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading sh... |
| CVE-2025-11160 | MEDIUM | 5.4 | 0.2% | Oct 15, 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in ... |
| CVE-2025-8561 | MEDIUM | 6.4 | 0.2% | Oct 15, 2025 | The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all vers... |
| CVE-2025-6042 | HIGH | 7.3 | 0.2% | Oct 15, 2025 | The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable ... |
| CVE-2025-55080 | HIGH | 7.1 | 0.1% | Oct 15, 2025 | In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allow... |
| CVE-2025-31702 | MEDIUM | 6.8 | 0.3% | Oct 15, 2025 | A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user cred... |
| CVE-2025-26861 | HIGH | 8.5 | 0.2% | Oct 15, 2025 | RemoteCall Remote Support Program (for Operator) versions prior to 5.3.0 contain an uncontrolled search path element vul... |
| CVE-2025-26860 | HIGH | 8.5 | 0.2% | Oct 15, 2025 | RemoteCall Remote Support Program (for Operator) versions prior to 5.1.0 contain an uncontrolled search path element vul... |
| CVE-2025-26859 | HIGH | 8.5 | 0.2% | Oct 15, 2025 | RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If ... |
| CVE-2025-11176 | MEDIUM | 4.3 | 0.2% | Oct 15, 2025 | The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ... |
| CVE-2025-10406 | MEDIUM | 5.5 | 0.2% | Oct 15, 2025 | The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now