2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2934MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, an...
CVE-2025-11340HIGH7.7GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certa...
CVE-2025-10249MEDIUM6.5The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missin...
CVE-2025-10004HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to ...
CVE-2025-39959MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: Fix incorrect retrival of acp_chip_...
CVE-2025-39958HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Make attach succeed when the device was...
CVE-2025-39957HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Curr...
CVE-2025-39956MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error Whe...
CVE-2025-39955HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconne...
CVE-2025-39954MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: mp: Fix dual-divider clock rate read...
CVE-2025-10862HIGH7.5The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr...
CVE-2025-11539CRITICAL9.9Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due ...
CVE-2025-11522CRITICAL9.8The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeo...
CVE-2025-7634CRITICAL9.8The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inc...
CVE-2025-7526CRITICAL9.8The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file...
CVE-2025-6038HIGH8.8The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable ...
CVE-2025-47355HIGH7.8Memory corruption while invoking remote procedure IOCTL calls.
CVE-2025-47354HIGH7.8Memory corruption while allocating buffers in DSP service.
CVE-2025-47351HIGH7.8Memory corruption while processing user buffers.
CVE-2025-47349HIGH7.8Memory corruption while processing an escape call.
CVE-2025-47347HIGH7.8Memory corruption while processing control commands in the virtual memory management interface.
CVE-2025-47342HIGH7.1Transient DOS may occur when multi-profile concurrency arises with QHS enabled.
CVE-2025-47341HIGH7.8memory corruption while processing an image encoding completion event.
CVE-2025-47340HIGH7.8Memory corruption while processing IOCTL call to get the mapping.
CVE-2025-47338HIGH7.8Memory corruption while processing escape commands from userspace.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now