2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71116 | HIGH | 7.1 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: make decode_pool() more resilient against ... |
| CVE-2025-71112 | HIGH | 7.1 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Cur... |
| CVE-2025-71110 | HIGH | 7.8 | 0.1% | Jan 14, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/slub: reset KASAN tag in defer_free() before acc... |
| CVE-2025-14317 | HIGH | 7.1 | 0.2% | Jan 14, 2026 | In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enume... |
| CVE-2025-66005 | HIGH | 8.5 | 0.2% | Jan 14, 2026 | Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Deni... |
| CVE-2025-14338 | HIGH | 8.5 | 0.2% | Jan 14, 2026 | Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v... |
| CVE-2025-0647 | HIGH | 7.9 | 0.2% | Jan 14, 2026 | In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a ... |
| CVE-2025-14770 | HIGH | 7.5 | 0.3% | Jan 14, 2026 | The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions... |
| CVE-2025-15378 | HIGH | 7.2 | 0.3% | Jan 14, 2026 | The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup... |
| CVE-2025-15283 | HIGH | 7.2 | 0.3% | Jan 14, 2026 | The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and ... |
| CVE-2025-15266 | HIGH | 7.2 | 0.2% | Jan 14, 2026 | The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Sto... |
| CVE-2025-14615 | HIGH | 7.1 | 0.1% | Jan 14, 2026 | The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2025-14613 | HIGH | 7.2 | 0.3% | Jan 14, 2026 | The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2025-68968 | HIGH | 7.8 | 0.1% | Jan 14, 2026 | Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affe... |
| CVE-2025-12053 | HIGH | 7.8 | 0.1% | Jan 14, 2026 | The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-... |
| CVE-2025-12052 | HIGH | 7.8 | 0.1% | Jan 14, 2026 | The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-... |
| CVE-2025-12051 | HIGH | 7.8 | 0.2% | Jan 14, 2026 | The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-... |
| CVE-2025-12050 | HIGH | 7.8 | 0.2% | Jan 14, 2026 | The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-... |
| CVE-2025-37186 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA)... |
| CVE-2025-68931 | HIGH | 7.5 | 0.2% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding... |
| CVE-2025-68704 | HIGH | 7.5 | 0.2% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.uti... |
| CVE-2025-68703 | HIGH | 7.5 | 0.1% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived ... |
| CVE-2025-68702 | HIGH | 7.5 | 0.1% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(... |
| CVE-2025-68701 | HIGH | 7.5 | 0.2% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses determin... |
| CVE-2025-68698 | HIGH | 7.5 | 0.1% | Jan 13, 2026 | Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Enc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now