2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-62371HIGH7.4OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSe...
CVE-2025-58133HIGH7.5Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a dis...
CVE-2025-20350HIGH7.5A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon...
CVE-2025-10577HIGH8.5Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research ...
CVE-2025-10576HIGH8.5Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research ...
CVE-2025-62370HIGH7.5Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered ...
CVE-2025-61990HIGH8.7When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microk...
CVE-2025-61935HIGH8.7When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the ...
CVE-2025-58071HIGH8.7When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to...
CVE-2025-57780HIGH8.8A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalat...
CVE-2025-8486HIGH8.5A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with el...
CVE-2025-10581HIGH8.5A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment t...
CVE-2025-61974HIGH8.7When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resour...
CVE-2025-61960HIGH8.7When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the ...
CVE-2025-61958HIGH8.7A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administ...
CVE-2025-61955HIGH8.8A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escala...
CVE-2025-61951HIGH8.7Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  This issue may occur when a Datagr...
CVE-2025-61938HIGH8.7When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for th...
CVE-2025-60016HIGH8.7When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cip...
CVE-2025-59781HIGH8.7When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increas...
CVE-2025-59778HIGH7.7When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause...
CVE-2025-59481HIGH8.7A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authentica...
CVE-2025-59478HIGH8.7When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can...
CVE-2025-59269HIGH8.4A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that...
CVE-2025-58120HIGH8.7When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now