2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-21647HIGH7.1In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flo...
CVE-2025-21631HIGH7.8In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix waker_bfqq UAF after bfq_split_bfqq...
CVE-2025-0566HIGH8.8A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13. This affects the function formSetDevNet...
CVE-2025-0308HIGH7.5The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-23209HIGH8.1Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote ...
CVE-2025-23207HIGH7.2KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted math...
CVE-2025-23206HIGH8.1The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure ...
CVE-2025-21606HIGH8.7stats is a macOS system monitor in for the menu bar. The Stats application is vulnerable to a local privilege escalation...
CVE-2025-21399HIGH7.4Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
CVE-2025-0430HIGH8.7Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remo...
CVE-2025-0531HIGH7.5A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown p...
CVE-2025-0530HIGH8.2A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability af...
CVE-2025-0529HIGH7.8A vulnerability, which was classified as critical, was found in code-projects Train Ticket Reservation System 1.0. This ...
CVE-2025-0528HIGH7.2A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by t...
CVE-2025-21325HIGH7.8Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2025-23915HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-23913HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma WordP...
CVE-2025-23912HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Philipp Speck Word...
CVE-2025-23911HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in solidres Solidres ...
CVE-2025-23902HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Taras Dashkevych Error Notification error-notification allows Cross S...
CVE-2025-23901HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in cybio GravatarLocalCache gravatarlocalcache allows Cross Site Request...
CVE-2025-23900HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in genkisan Genki Announcement genki-announcement allows Cross Site Requ...
CVE-2025-23898HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in ivobrett Apply with LinkedIn buttons apply-with-linkedin-buttons allo...
CVE-2025-23895HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Dan Cameron Add RSS add-rss allows Stored XSS.This issue affects Add ...
CVE-2025-23884HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Chris Roberts Annie annie allows Cross Site Request Forgery.This issu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now