2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2934 | MEDIUM | 6.5 | 0.5% | Oct 9, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, an... |
| CVE-2025-11340 | HIGH | 7.7 | 0.3% | Oct 9, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certa... |
| CVE-2025-10249 | MEDIUM | 6.5 | 0.3% | Oct 9, 2025 | The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missin... |
| CVE-2025-10004 | HIGH | 7.5 | 0.5% | Oct 9, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to ... |
| CVE-2025-39959 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: Fix incorrect retrival of acp_chip_... |
| CVE-2025-39958 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Make attach succeed when the device was... |
| CVE-2025-39957 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Curr... |
| CVE-2025-39956 | MEDIUM | 5.5 | 0.2% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error Whe... |
| CVE-2025-39955 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconne... |
| CVE-2025-39954 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: mp: Fix dual-divider clock rate read... |
| CVE-2025-10862 | HIGH | 7.5 | 0.4% | Oct 9, 2025 | The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr... |
| CVE-2025-11539 | CRITICAL | 9.9 | 0.6% | Oct 9, 2025 | Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due ... |
| CVE-2025-11522 | CRITICAL | 9.8 | 0.5% | Oct 9, 2025 | The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeo... |
| CVE-2025-7634 | CRITICAL | 9.8 | 0.8% | Oct 9, 2025 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inc... |
| CVE-2025-7526 | CRITICAL | 9.8 | 0.8% | Oct 9, 2025 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file... |
| CVE-2025-6038 | HIGH | 8.8 | 0.3% | Oct 9, 2025 | The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable ... |
| CVE-2025-47355 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | Memory corruption while invoking remote procedure IOCTL calls. |
| CVE-2025-47354 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | Memory corruption while allocating buffers in DSP service. |
| CVE-2025-47351 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | Memory corruption while processing user buffers. |
| CVE-2025-47349 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | Memory corruption while processing an escape call. |
| CVE-2025-47347 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | Memory corruption while processing control commands in the virtual memory management interface. |
| CVE-2025-47342 | HIGH | 7.1 | 0.1% | Oct 9, 2025 | Transient DOS may occur when multi-profile concurrency arises with QHS enabled. |
| CVE-2025-47341 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | memory corruption while processing an image encoding completion event. |
| CVE-2025-47340 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | Memory corruption while processing IOCTL call to get the mapping. |
| CVE-2025-47338 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | Memory corruption while processing escape commands from userspace. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now