2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38562 | MEDIUM | 5.5 | 7.1% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference error in genera... |
| CVE-2025-38561 | MEDIUM | 4.7 | 0.4% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Preauh_HashValue race condition If clie... |
| CVE-2025-38560 | MEDIUM | 5.5 | 0.2% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/sev: Evict cache lines during SNP memory valida... |
| CVE-2025-38559 | MEDIUM | 5.5 | 0.1% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmt: fix a crashlog NULL pointer... |
| CVE-2025-38558 | MEDIUM | 5.5 | 0.1% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Initialize frame-based format col... |
| CVE-2025-38557 | MEDIUM | 5.5 | 0.1% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: HID: apple: validate feature-report field count to ... |
| CVE-2025-38556 | HIGH | 7.1 | 0.1% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: HID: core: Harden s32ton() against conversion to 0 ... |
| CVE-2025-38555 | HIGH | 7.8 | 0.2% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_c... |
| CVE-2025-38554 | HIGH | 7.8 | 0.2% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm: fix a UAF when vma->mm is freed after vma->vm_r... |
| CVE-2025-9146 | HIGH | 8.1 | 0.5% | Aug 19, 2025 | A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file c... |
| CVE-2025-9145 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file ... |
| CVE-2025-8782 | — | — | — | Aug 19, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-51540 | MEDIUM | 5.3 | 0.2% | Aug 19, 2025 | EzGED3 3.5.0 stores user passwords using an insecure hashing scheme: md5(md5(password)). This hashing method is cryptogr... |
| CVE-2025-51539 | MEDIUM | 5.3 | 0.7% | Aug 19, 2025 | EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficie... |
| CVE-2025-50938 | MEDIUM | 6.1 | 0.2% | Aug 19, 2025 | Cross site scripting (XSS) vulnerability in Hustoj 2025-01-31 via the TID parameter to thread.php. |
| CVE-2025-50434 | MEDIUM | 5.3 | 0.2% | Aug 19, 2025 | A security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is... |
| CVE-2025-43738 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025... |
| CVE-2025-9144 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A weakness has been identified in Scada-LTS 2.7.8.1. This vulnerability affects unknown code of the file publisher_edit.... |
| CVE-2025-9143 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. T... |
| CVE-2025-51529 | MEDIUM | 5.3 | 0.5% | Aug 19, 2025 | Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin th... |
| CVE-2025-51510 | MEDIUM | 4.9 | 0.5% | Aug 19, 2025 | MoonShine was discovered to contain a SQL injection vulnerability under the Blog -> Categories page when using the moons... |
| CVE-2025-51489 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upl... |
| CVE-2025-51488 | MEDIUM | 4.9 | 0.5% | Aug 19, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to sto... |
| CVE-2025-51487 | MEDIUM | 4.5 | 0.4% | Aug 19, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary Ja... |
| CVE-2025-50897 | MEDIUM | 4.3 | 0.3% | Aug 19, 2025 | A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now