2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71236MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate sp before freeing associate...
CVE-2025-71235MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Delay module unload while fabric sca...
CVE-2025-71234HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_...
CVE-2025-71233MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Avoid creating sub-groups asynchrono...
CVE-2025-71232MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Free sp in error path to fix system ...
CVE-2025-71231HIGH7.1In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix out-of-bounds index in find_empty...
CVE-2025-71230MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hfs: ensure sb->s_fs_info is always cleaned up Whe...
CVE-2025-71229MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix alignment fault in rtw_core_enable...
CVE-2025-70998CRITICAL9.8UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the tel...
CVE-2025-65791CRITICAL9.8ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user i...
CVE-2025-65519MEDIUM6.5mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processin...
CVE-2025-15579CRITICAL9.5Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerabi...
CVE-2025-71228Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71227MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't WARN for connections on inval...
CVE-2025-71226Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71225MEDIUM5.3In the Linux kernel, the following vulnerability has been resolved: md: suspend array while updating raid_disks via sys...
CVE-2025-61982HIGH7.8An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A ...
CVE-2025-8308MEDIUM6.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Key Softwar...
CVE-2025-60038HIGH8.8A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the...
CVE-2025-60037HIGH8.8A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the...
CVE-2025-60036HIGH8.8A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions ...
CVE-2025-60035HIGH8.8A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions...
CVE-2025-59920HIGH8.6When hours are entered in time@work, version 7.0.5, it performs a query to display the projects assigned to the user. If...
CVE-2025-33253HIGH7.3NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user ...
CVE-2025-33252HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now