2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-39843MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm: slub: avoid wake up kswapd in set_track_prepare...
CVE-2025-39842MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ocfs2: prevent release journal inode after journal ...
CVE-2025-39841HIGH7.8In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred...
CVE-2025-39840HIGH7.1In the Linux kernel, the following vulnerability has been resolved: audit: fix out-of-bounds read in audit_compare_dnam...
CVE-2025-39839HIGH7.1In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix OOB read/write in network-coding de...
CVE-2025-39838MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL pointer dereference in UTF16 con...
CVE-2025-39837HIGH7.8In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: Fix racy registrations asu...
CVE-2025-10718MEDIUM5.3A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the ...
CVE-2025-8664MEDIUM6.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Comp...
CVE-2025-8532MEDIUM6.4Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade...
CVE-2025-57528HIGH7.7An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of servic...
CVE-2025-10717MEDIUM5.3A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unkno...
CVE-2025-10716MEDIUM5.3A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functio...
CVE-2025-58114MEDIUM4.8Improper Input Validation vulnerability in Hallo Welt! GmbH BlueSpice (Extension:CognitiveProcessDesigner) allows Cross-...
CVE-2025-57880MEDIUM5.4Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) all...
CVE-2025-48007MEDIUM6.4Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows ...
CVE-2025-46703MEDIUM6.4Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-...
CVE-2025-10715MEDIUM5.3A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an ...
CVE-2025-10712HIGH7.3A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This issue affects some unknown processing...
CVE-2025-7665HIGH8.1The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missin...
CVE-2025-10711MEDIUM4.3A vulnerability has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This vulnerability affects unknown co...
CVE-2025-10710MEDIUM4.3A flaw has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This affects an unknown part of the file /inde...
CVE-2025-9969HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web D...
CVE-2025-10709HIGH7.5A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is som...
CVE-2025-10708HIGH7.5A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by thi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now