2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-39978HIGH7.8In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix potential use after free in otx2_...
CVE-2025-39977HIGH7.8In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI sy...
CVE-2025-39976HIGH7.8In the Linux kernel, the following vulnerability has been resolved: futex: Use correct exit on failure from futex_hash_...
CVE-2025-39975CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix wrong index reference in smb2_comp...
CVE-2025-39974In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix slab-out-of-bounds in _parse_i...
CVE-2025-39973HIGH8.8In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_...
CVE-2025-39972HIGH8.8In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in i40e_validate_queue_map...
CVE-2025-39971HIGH8.8In the Linux kernel, the following vulnerability has been resolved: i40e: fix idx validation in config queues msg Ensu...
CVE-2025-39970HIGH8.8In the Linux kernel, the following vulnerability has been resolved: i40e: fix input validation logic for action_meta F...
CVE-2025-39969HIGH8.8In the Linux kernel, the following vulnerability has been resolved: i40e: fix validation of VF state in get resources ...
CVE-2025-39968HIGH7.3In the Linux kernel, the following vulnerability has been resolved: i40e: add max boundary check for VF filters There ...
CVE-2025-39967HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fbcon: fix integer overflow in fbcon_do_set_font F...
CVE-2025-39966HIGH7In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix race during abort for file descriptors...
CVE-2025-11501HIGH7.5The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all v...
CVE-2025-11161MEDIUM5.4The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading sh...
CVE-2025-11160MEDIUM5.4The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in ...
CVE-2025-8561MEDIUM6.4The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all vers...
CVE-2025-6042HIGH7.3The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable ...
CVE-2025-55080HIGH7.1In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allow...
CVE-2025-31702MEDIUM6.8A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user cred...
CVE-2025-26861HIGH8.5RemoteCall Remote Support Program (for Operator) versions prior to 5.3.0 contain an uncontrolled search path element vul...
CVE-2025-26860HIGH8.5RemoteCall Remote Support Program (for Operator) versions prior to 5.1.0 contain an uncontrolled search path element vul...
CVE-2025-26859HIGH8.5RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If ...
CVE-2025-11176MEDIUM4.3The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2025-10406MEDIUM5.5The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now