2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-38562MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference error in genera...
CVE-2025-38561MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Preauh_HashValue race condition If clie...
CVE-2025-38560MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/sev: Evict cache lines during SNP memory valida...
CVE-2025-38559MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmt: fix a crashlog NULL pointer...
CVE-2025-38558MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Initialize frame-based format col...
CVE-2025-38557MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: HID: apple: validate feature-report field count to ...
CVE-2025-38556HIGH7.1In the Linux kernel, the following vulnerability has been resolved: HID: core: Harden s32ton() against conversion to 0 ...
CVE-2025-38555HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_c...
CVE-2025-38554HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm: fix a UAF when vma->mm is freed after vma->vm_r...
CVE-2025-9146HIGH8.1A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file c...
CVE-2025-9145MEDIUM5.4A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file ...
CVE-2025-8782Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-51540MEDIUM5.3EzGED3 3.5.0 stores user passwords using an insecure hashing scheme: md5(md5(password)). This hashing method is cryptogr...
CVE-2025-51539MEDIUM5.3EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficie...
CVE-2025-50938MEDIUM6.1Cross site scripting (XSS) vulnerability in Hustoj 2025-01-31 via the TID parameter to thread.php.
CVE-2025-50434MEDIUM5.3A security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is...
CVE-2025-43738MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-9144MEDIUM5.4A weakness has been identified in Scada-LTS 2.7.8.1. This vulnerability affects unknown code of the file publisher_edit....
CVE-2025-9143MEDIUM5.4A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. T...
CVE-2025-51529MEDIUM5.3Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin th...
CVE-2025-51510MEDIUM4.9MoonShine was discovered to contain a SQL injection vulnerability under the Blog -> Categories page when using the moons...
CVE-2025-51489MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upl...
CVE-2025-51488MEDIUM4.9A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to sto...
CVE-2025-51487MEDIUM4.5A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary Ja...
CVE-2025-50897MEDIUM4.3A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now