2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54282 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Heap-based Buffer Overflow vulnerability that cou... |
| CVE-2025-54281 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Use After Free vulnerability that could result in... |
| CVE-2025-54276 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Substance3D - Modeler versions 1.22.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a cra... |
| CVE-2025-54280 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-54274 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Substance3D - Viewer versions 0.25.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could ... |
| CVE-2025-54273 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-33182 | HIGH | 7.6 | 0.3% | Oct 14, 2025 | NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause... |
| CVE-2025-60536 | HIGH | 7.5 | 0.6% | Oct 14, 2025 | An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Servi... |
| CVE-2025-57618 | HIGH | 7.3 | 0.7% | Oct 14, 2025 | A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the s... |
| CVE-2025-23356 | HIGH | 8.4 | 0.1% | Oct 14, 2025 | NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might... |
| CVE-2025-60535 | HIGH | 7.3 | 0.2% | Oct 14, 2025 | A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to e... |
| CVE-2025-59502 | HIGH | 7.5 | 1.0% | Oct 14, 2025 | Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over ... |
| CVE-2025-59494 | HIGH | 7.8 | 0.6% | Oct 14, 2025 | Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59295 | HIGH | 8.8 | 1.8% | Oct 14, 2025 | Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. |
| CVE-2025-59292 | HIGH | 8.2 | 0.4% | Oct 14, 2025 | External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate... |
| CVE-2025-59291 | HIGH | 8.2 | 0.4% | Oct 14, 2025 | External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate... |
| CVE-2025-59290 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59289 | HIGH | 7 | 0.2% | Oct 14, 2025 | Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59285 | HIGH | 7 | 0.7% | Oct 14, 2025 | Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59282 | HIGH | 7 | 0.6% | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows ... |
| CVE-2025-59281 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to ... |
| CVE-2025-59278 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat... |
| CVE-2025-59277 | HIGH | 7.8 | 0.3% | Oct 14, 2025 | Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat... |
| CVE-2025-59275 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat... |
| CVE-2025-59261 | HIGH | 7 | 0.2% | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to eleva... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now