2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-37147 | HIGH | 7.1 | 0.1% | Oct 14, 2025 | A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root... |
| CVE-2025-37146 | HIGH | 7.2 | 0.8% | Oct 14, 2025 | A vulnerability in the web-based management interface of network access point configuration services could allow an auth... |
| CVE-2025-37134 | HIGH | 7.2 | 1.3% | Oct 14, 2025 | An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor oper... |
| CVE-2025-37133 | HIGH | 7.2 | 1.3% | Oct 14, 2025 | An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor oper... |
| CVE-2025-37132 | HIGH | 7.2 | 0.5% | Oct 14, 2025 | An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Contr... |
| CVE-2025-25004 | HIGH | 7.3 | 0.4% | Oct 14, 2025 | Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24990 | HIGH | 7.8 | 5.8% | Oct 14, 2025 | Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows o... |
| CVE-2025-24052 | HIGH | 7.8 | 2.3% | Oct 14, 2025 | Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows o... |
| CVE-2025-62172 | HIGH | 8.5 | 0.5% | Oct 14, 2025 | Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 t... |
| CVE-2025-57741 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, ... |
| CVE-2025-57740 | HIGH | 8.8 | 0.6% | Oct 14, 2025 | An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, versi... |
| CVE-2025-57716 | HIGH | 7.3 | 0.2% | Oct 14, 2025 | An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.... |
| CVE-2025-46774 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2... |
| CVE-2025-31365 | HIGH | 7.1 | 0.3% | Oct 14, 2025 | An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.... |
| CVE-2025-25253 | HIGH | 7.5 | 0.1% | Oct 14, 2025 | An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, ... |
| CVE-2025-22258 | HIGH | 7.2 | 0.5% | Oct 14, 2025 | A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0... |
| CVE-2025-11577 | HIGH | 7.6 | 0.2% | Oct 14, 2025 | Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot ... |
| CVE-2025-62156 | HIGH | 8.8 | 0.5% | Oct 14, 2025 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version... |
| CVE-2025-5946 | HIGH | 7.2 | 13.8% | Oct 14, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Inf... |
| CVE-2025-10985 | HIGH | 7.2 | 21.1% | Oct 14, 2025 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a... |
| CVE-2025-10243 | HIGH | 7.2 | 21.1% | Oct 14, 2025 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a... |
| CVE-2025-10242 | HIGH | 7.2 | 21.1% | Oct 14, 2025 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote a... |
| CVE-2025-47856 | HIGH | 7.2 | 1.4% | Oct 14, 2025 | Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] ... |
| CVE-2025-33044 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bou... |
| CVE-2025-22833 | HIGH | 7.3 | 0.1% | Oct 14, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by loca... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now