2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58188 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that as... |
| CVE-2025-58187 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with ... |
| CVE-2025-54546 | HIGH | 7.5 | 0.2% | Oct 29, 2025 | On affected platforms, restricted users could use SSH port forwarding to access host-internal services |
| CVE-2025-54545 | HIGH | 7.8 | 0.1% | Oct 29, 2025 | On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privil... |
| CVE-2025-54459 | HIGH | 8.7 | 0.4% | Oct 29, 2025 | Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd witho... |
| CVE-2025-9871 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local ... |
| CVE-2025-9870 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability all... |
| CVE-2025-9869 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local at... |
| CVE-2025-11465 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remot... |
| CVE-2025-11464 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2025-11463 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows rem... |
| CVE-2025-10934 | HIGH | 7.8 | 0.5% | Oct 29, 2025 | GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2025-10925 | HIGH | 7.8 | 2.8% | Oct 29, 2025 | GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote... |
| CVE-2025-10924 | HIGH | 7.8 | 0.4% | Oct 29, 2025 | GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to... |
| CVE-2025-10923 | HIGH | 7.8 | 0.4% | Oct 29, 2025 | GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers ... |
| CVE-2025-10922 | HIGH | 7.8 | 0.6% | Oct 29, 2025 | GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2025-10921 | HIGH | 7.8 | 0.5% | Oct 29, 2025 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2025-10920 | HIGH | 7.8 | 0.4% | Oct 29, 2025 | GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attacke... |
| CVE-2025-64104 | HIGH | 7.3 | 0.2% | Oct 29, 2025 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2025-64101 | HIGH | 8.8 | 0.3% | Oct 29, 2025 | Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability e... |
| CVE-2025-62797 | HIGH | 8.6 | 0.2% | Oct 29, 2025 | FluxCP is a web-based Control Panel for rAthena servers written in PHP. A critical Cross-Site Request Forgery (CSRF) vul... |
| CVE-2025-57227 | HIGH | 7.8 | 0.1% | Oct 29, 2025 | An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via ... |
| CVE-2025-11232 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at th... |
| CVE-2025-62792 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer ... |
| CVE-2025-62791 | HIGH | 7.5 | 0.3% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, DecodeCis... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now