2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-39676MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: qla4xxx: Prevent a potential error pointer de...
CVE-2025-39675MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null pointer check in mod_hdcp...
CVE-2025-39674MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: ufs-qcom: Fix ESI null pointer dereferen...
CVE-2025-39673MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: ppp: fix race conditions in ppp_fill_forward_path ...
CVE-2025-38737MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix s...
CVE-2025-38736HIGH7.1In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: Fix PHY address mask in MDI...
CVE-2025-38735MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gve: prevent ethtool ops after shutdown A crash ca...
CVE-2025-38734HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF on smcsk after smc_listen_out() B...
CVE-2025-38733MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: s390/mm: Do not map lowcore with identity mapping ...
CVE-2025-38732MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject: don't leak dst refcount for l...
CVE-2025-38731HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix vm_bind_ioctl double free bug If the a...
CVE-2025-35452CRITICAL9.8PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative ...
CVE-2025-35451CRITICAL9.8PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The...
CVE-2025-30200MEDIUM6.3ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption ke...
CVE-2025-30199HIGH7.5ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to ba...
CVE-2025-30198MEDIUM6.3ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which c...
CVE-2025-10014LOW3.1A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/upda...
CVE-2025-9999HIGH7.6Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on...
CVE-2025-9998MEDIUM6The sequence of packets received by a Networking server are not correctly checked. An attacker could exploit this vulne...
CVE-2025-58628CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Mirac...
CVE-2025-58440Rejected reason: The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager.
CVE-2025-58214HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58206CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-57889HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54744MEDIUM6.5Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now