2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20715 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20714 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20713 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20712 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (... |
| CVE-2025-20711 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (... |
| CVE-2025-20710 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proxim... |
| CVE-2025-20709 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (... |
| CVE-2025-10228 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affect... |
| CVE-2025-41718 | HIGH | 7.5 | 0.2% | Oct 14, 2025 | A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote a... |
| CVE-2025-41699 | HIGH | 8.8 | 0.9% | Oct 14, 2025 | An low privileged remote attacker with an account for the Web-based management can change the system configuration to pe... |
| CVE-2025-41703 | HIGH | 7.5 | 1.0% | Oct 14, 2025 | An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command... |
| CVE-2025-59889 | HIGH | 8.6 | 0.2% | Oct 14, 2025 | Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of a... |
| CVE-2025-62363 | HIGH | 7.8 | 0.2% | Oct 13, 2025 | yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the applicati... |
| CVE-2025-62360 | HIGH | 8.8 | 0.8% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Inj... |
| CVE-2025-62179 | HIGH | 8.8 | 0.4% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL In... |
| CVE-2025-62177 | HIGH | 8.8 | 0.5% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL In... |
| CVE-2025-9713 | HIGH | 8.8 | 14.5% | Oct 13, 2025 | Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve re... |
| CVE-2025-61688 | HIGH | 7.5 | 0.3% | Oct 13, 2025 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensit... |
| CVE-2025-59836 | HIGH | 7.5 | 0.5% | Oct 13, 2025 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer... |
| CVE-2025-11622 | HIGH | 7.8 | 0.7% | Oct 13, 2025 | Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to esc... |
| CVE-2025-62170 | HIGH | 7.5 | 0.3% | Oct 13, 2025 | rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality... |
| CVE-2025-7707 | HIGH | 7.8 | 0.2% | Oct 13, 2025 | The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which... |
| CVE-2025-11695 | HIGH | 7.5 | 0.2% | Oct 13, 2025 | When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects M... |
| CVE-2025-43991 | HIGH | 7.1 | 0.1% | Oct 13, 2025 | SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain... |
| CVE-2025-37729 | HIGH | 7.2 | 0.6% | Oct 13, 2025 | Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a ma... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now