2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21647 | HIGH | 7.1 | 0.3% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flo... |
| CVE-2025-21631 | HIGH | 7.8 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix waker_bfqq UAF after bfq_split_bfqq... |
| CVE-2025-0566 | HIGH | 8.8 | 8.7% | Jan 19, 2025 | A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13. This affects the function formSetDevNet... |
| CVE-2025-0308 | HIGH | 7.5 | 0.5% | Jan 18, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2025-23209 | HIGH | 8.1 | 4.1% | Jan 18, 2025 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote ... |
| CVE-2025-23207 | HIGH | 7.2 | 0.4% | Jan 17, 2025 | KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted math... |
| CVE-2025-23206 | HIGH | 8.1 | 0.3% | Jan 17, 2025 | The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure ... |
| CVE-2025-21606 | HIGH | 8.7 | 0.3% | Jan 17, 2025 | stats is a macOS system monitor in for the menu bar. The Stats application is vulnerable to a local privilege escalation... |
| CVE-2025-21399 | HIGH | 7.4 | 0.7% | Jan 17, 2025 | Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability |
| CVE-2025-0430 | HIGH | 8.7 | 0.5% | Jan 17, 2025 | Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remo... |
| CVE-2025-0531 | HIGH | 7.5 | 0.4% | Jan 17, 2025 | A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown p... |
| CVE-2025-0530 | HIGH | 8.2 | 0.5% | Jan 17, 2025 | A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability af... |
| CVE-2025-0529 | HIGH | 7.8 | 0.4% | Jan 17, 2025 | A vulnerability, which was classified as critical, was found in code-projects Train Ticket Reservation System 1.0. This ... |
| CVE-2025-0528 | HIGH | 7.2 | 5.8% | Jan 17, 2025 | A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by t... |
| CVE-2025-21325 | HIGH | 7.8 | 0.4% | Jan 17, 2025 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2025-23915 | HIGH | 7.5 | 1.0% | Jan 16, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-23913 | HIGH | 8.5 | 0.5% | Jan 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma WordP... |
| CVE-2025-23912 | HIGH | 8.5 | 0.5% | Jan 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Philipp Speck Word... |
| CVE-2025-23911 | HIGH | 8.5 | 0.5% | Jan 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in solidres Solidres ... |
| CVE-2025-23902 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Taras Dashkevych Error Notification error-notification allows Cross S... |
| CVE-2025-23901 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in cybio GravatarLocalCache gravatarlocalcache allows Cross Site Request... |
| CVE-2025-23900 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in genkisan Genki Announcement genki-announcement allows Cross Site Requ... |
| CVE-2025-23898 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ivobrett Apply with LinkedIn buttons apply-with-linkedin-buttons allo... |
| CVE-2025-23895 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Dan Cameron Add RSS add-rss allows Stored XSS.This issue affects Add ... |
| CVE-2025-23884 | HIGH | 7.1 | 0.2% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Chris Roberts Annie annie allows Cross Site Request Forgery.This issu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now