2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-38684MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: use old 'nbands' while purging unus...
CVE-2025-38683MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Fix panic during namespace deletion with...
CVE-2025-38682HIGH7.8In the Linux kernel, the following vulnerability has been resolved: i2c: core: Fix double-free of fwnode in i2c_unregis...
CVE-2025-38681MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: take the memory hotplug lock inside ptdu...
CVE-2025-38680HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in u...
CVE-2025-38679HIGH7.1In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload b...
CVE-2025-23302MEDIUM4.2NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsaf...
CVE-2025-23301MEDIUM4.2NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsa...
CVE-2025-23262MEDIUM6.3NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause in...
CVE-2025-23261MEDIUM5.5NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed ...
CVE-2025-23259MEDIUM6.5NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might b...
CVE-2025-23258HIGH7.3NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker wit...
CVE-2025-23257HIGH7.3NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privile...
CVE-2025-23256HIGH8.7NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause i...
CVE-2025-8311CRITICAL9.4dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpo...
CVE-2025-6785MEDIUM4.7Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of ...
CVE-2025-2694MEDIUM4.8IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 ...
CVE-2025-2667MEDIUM4.9IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 ...
CVE-2025-25048MEDIUM6.5IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allo...
CVE-2025-57263HIGH7.2An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious...
CVE-2025-7388HIGH8.4It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing a...
CVE-2025-7385CRITICAL9.3Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, ...
CVE-2025-41063MEDIUM5.4A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to...
CVE-2025-41062MEDIUM5.4A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to...
CVE-2025-41061MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now