2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71097 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix reference count leak when using error rou... |
| CVE-2025-71096 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Check for the presence of LS_NLA_TYPE_DG... |
| CVE-2025-71095 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix the crash issue for zero copy XDP_... |
| CVE-2025-71094 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: validate PHY address before use Th... |
| CVE-2025-71090 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd_file reference leak in nfsd4_add_rda... |
| CVE-2025-71088 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fallback earlier on simult connection Syzka... |
| CVE-2025-71087 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: iavf: fix off-by-one issues in iavf_config_rss_reg(... |
| CVE-2025-71085 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calips... |
| CVE-2025-71084 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/cm: Fix leaking the multicast GID table refere... |
| CVE-2025-71083 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Avoid NULL pointer deref for evicted BOs ... |
| CVE-2025-71081 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: stm32: sai: fix OF node leak on probe The re... |
| CVE-2025-71080 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix a BUG in rt6_get_pcpu_route() under PREEM... |
| CVE-2025-71079 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: nfc: fix deadlock between nfc_unregister_devic... |
| CVE-2025-71077 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: tpm: Cap the number of PCR banks tpm2_get_pcr_allo... |
| CVE-2025-71076 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Limit num_syncs to prevent oversized all... |
| CVE-2025-71074 | MEDIUM | 4.7 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: functionfs: fix the open/removal races ffs_epfile_... |
| CVE-2025-71072 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: shmem: fix recovery on rename failures maple_tree ... |
| CVE-2025-68823 | MEDIUM | 5.5 | 0.1% | Jan 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ublk: fix deadlock when reading partition table Wh... |
| CVE-2025-55462 | MEDIUM | 6.5 | 0.4% | Jan 13, 2026 | A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header ... |
| CVE-2025-13447 | MEDIUM | 6.8 | 25.4% | Jan 13, 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker ... |
| CVE-2025-13444 | MEDIUM | 6.8 | 25.4% | Jan 13, 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker ... |
| CVE-2025-9435 | MEDIUM | 5.5 | 0.5% | Jan 13, 2026 | Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module |
| CVE-2025-14507 | MEDIUM | 5.3 | 0.4% | Jan 13, 2026 | The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Expos... |
| CVE-2025-59021 | MEDIUM | 6.4 | 0.2% | Jan 13, 2026 | Backend users with access to the redirects module and write permission on the sys_redirect table were able to read, crea... |
| CVE-2025-59020 | MEDIUM | 6.5 | 0.3% | Jan 13, 2026 | By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now