2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15578CRITICAL9.8Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the sys...
CVE-2025-65717MEDIUM4.3An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction w...
CVE-2025-65716HIGH8.8An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code v...
CVE-2025-65715HIGH7.8An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to...
CVE-2025-14573LOW2.7Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team...
CVE-2025-14350MEDIUM4.3Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership whe...
CVE-2025-2418MEDIUM4.3URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall a...
CVE-2025-13821MEDIUM5.7Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket ...
CVE-2025-59905MEDIUM6.1Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endp...
CVE-2025-59904MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kFo...
CVE-2025-59903MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This ...
CVE-2025-32063MEDIUM6.8There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens d...
CVE-2025-32062HIGH8.8The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos...
CVE-2025-32061HIGH8.8The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos...
CVE-2025-32060MEDIUM6.7The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on be...
CVE-2025-32059HIGH8.8The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bos...
CVE-2025-32058CRITICAL9.3The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment...
CVE-2025-71224In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: ocb: skip rx_no_sta when interface ...
CVE-2025-71223MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in smb2_open() When ...
CVE-2025-71222MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: ensure skb headroom before skb_push ...
CVE-2025-71221HIGH7In the Linux kernel, the following vulnerability has been resolved: dmaengine: mmp_pdma: Fix race condition in mmp_pdma...
CVE-2025-71220HIGH7.8In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_session_rpc_close() on error...
CVE-2025-71204MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in parse_durable_hand...
CVE-2025-71203HIGH7In the Linux kernel, the following vulnerability has been resolved: riscv: Sanitize syscall table indexing under specul...
CVE-2025-71202MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iommu/sva: invalidate stale IOTLB entries for kerne...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now