2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39843 | MEDIUM | 5.5 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm: slub: avoid wake up kswapd in set_track_prepare... |
| CVE-2025-39842 | MEDIUM | 5.5 | 0.2% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: prevent release journal inode after journal ... |
| CVE-2025-39841 | HIGH | 7.8 | 0.2% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix buffer free/clear order in deferred... |
| CVE-2025-39840 | HIGH | 7.1 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: audit: fix out-of-bounds read in audit_compare_dnam... |
| CVE-2025-39839 | HIGH | 7.1 | 0.2% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix OOB read/write in network-coding de... |
| CVE-2025-39838 | MEDIUM | 5.5 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL pointer dereference in UTF16 con... |
| CVE-2025-39837 | HIGH | 7.8 | 0.1% | Sep 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: Fix racy registrations asu... |
| CVE-2025-10718 | MEDIUM | 5.3 | 0.1% | Sep 19, 2025 | A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the ... |
| CVE-2025-8664 | MEDIUM | 6.3 | 0.2% | Sep 19, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Comp... |
| CVE-2025-8532 | MEDIUM | 6.4 | 0.1% | Sep 19, 2025 | Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade... |
| CVE-2025-57528 | HIGH | 7.7 | 0.4% | Sep 19, 2025 | An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of servic... |
| CVE-2025-10717 | MEDIUM | 5.3 | 0.1% | Sep 19, 2025 | A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unkno... |
| CVE-2025-10716 | MEDIUM | 5.3 | 0.1% | Sep 19, 2025 | A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functio... |
| CVE-2025-58114 | MEDIUM | 4.8 | 0.2% | Sep 19, 2025 | Improper Input Validation vulnerability in Hallo Welt! GmbH BlueSpice (Extension:CognitiveProcessDesigner) allows Cross-... |
| CVE-2025-57880 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) all... |
| CVE-2025-48007 | MEDIUM | 6.4 | 0.2% | Sep 19, 2025 | Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows ... |
| CVE-2025-46703 | MEDIUM | 6.4 | 0.2% | Sep 19, 2025 | Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-... |
| CVE-2025-10715 | MEDIUM | 5.3 | 0.1% | Sep 19, 2025 | A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an ... |
| CVE-2025-10712 | HIGH | 7.3 | 0.3% | Sep 19, 2025 | A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This issue affects some unknown processing... |
| CVE-2025-7665 | HIGH | 8.1 | 0.3% | Sep 19, 2025 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missin... |
| CVE-2025-10711 | MEDIUM | 4.3 | 0.3% | Sep 19, 2025 | A vulnerability has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This vulnerability affects unknown co... |
| CVE-2025-10710 | MEDIUM | 4.3 | 0.3% | Sep 19, 2025 | A flaw has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This affects an unknown part of the file /inde... |
| CVE-2025-9969 | HIGH | 7.1 | 0.2% | Sep 19, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web D... |
| CVE-2025-10709 | HIGH | 7.5 | 0.9% | Sep 19, 2025 | A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is som... |
| CVE-2025-10708 | HIGH | 7.5 | 0.9% | Sep 19, 2025 | A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by thi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now