2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-71116HIGH7.1In the Linux kernel, the following vulnerability has been resolved: libceph: make decode_pool() more resilient against ...
CVE-2025-71112HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Cur...
CVE-2025-71110HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm/slub: reset KASAN tag in defer_free() before acc...
CVE-2025-14317HIGH7.1In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enume...
CVE-2025-66005HIGH8.5Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Deni...
CVE-2025-14338HIGH8.5Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v...
CVE-2025-0647HIGH7.9In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a ...
CVE-2025-14770HIGH7.5The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions...
CVE-2025-15378HIGH7.2The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup...
CVE-2025-15283HIGH7.2The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and ...
CVE-2025-15266HIGH7.2The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Sto...
CVE-2025-14615HIGH7.1The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2025-14613HIGH7.2The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu...
CVE-2025-68968HIGH7.8Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affe...
CVE-2025-12053HIGH7.8The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-...
CVE-2025-12052HIGH7.8The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-...
CVE-2025-12051HIGH7.8The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-...
CVE-2025-12050HIGH7.8The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-...
CVE-2025-37186HIGH7.8A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA)...
CVE-2025-68931HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding...
CVE-2025-68704HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.uti...
CVE-2025-68703HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived ...
CVE-2025-68702HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(...
CVE-2025-68701HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses determin...
CVE-2025-68698HIGH7.5Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Enc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now