2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23309 | HIGH | 8.2 | 0.2% | Oct 10, 2025 | NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of ... |
| CVE-2025-23282 | HIGH | 7 | 0.2% | Oct 10, 2025 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to esca... |
| CVE-2025-23280 | HIGH | 7 | 0.2% | Oct 10, 2025 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful ex... |
| CVE-2025-61689 | HIGH | 8.7 | 0.3% | Oct 10, 2025 | HTTP.jl is an HTTP client and server functionality for the Julia programming language. Prior to version 1.10.19, HTTP.jl... |
| CVE-2025-60305 | HIGH | 8.8 | 0.4% | Oct 10, 2025 | SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a... |
| CVE-2025-59530 | HIGH | 7.5 | 0.4% | Oct 10, 2025 | quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving ... |
| CVE-2025-48043 | HIGH | 8.6 | 0.5% | Oct 10, 2025 | Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated ... |
| CVE-2025-60869 | HIGH | 7.3 | 0.2% | Oct 10, 2025 | Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fie... |
| CVE-2025-60378 | HIGH | 8.1 | 1.1% | Oct 10, 2025 | Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into in... |
| CVE-2025-61864 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially craft... |
| CVE-2025-61863 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening sp... |
| CVE-2025-61862 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening sp... |
| CVE-2025-61861 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially ... |
| CVE-2025-61860 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening sp... |
| CVE-2025-61859 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Open... |
| CVE-2025-61858 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening speci... |
| CVE-2025-61857 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlie... |
| CVE-2025-61856 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earl... |
| CVE-2025-52625 | HIGH | 7.5 | 0.2% | Oct 10, 2025 | A vulnerability Cacheable SSL Page Found vulnerability has been identified in HCL AION. Cached data may expose cre... |
| CVE-2025-11189 | HIGH | 7.3 | 0.4% | Oct 10, 2025 | The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, ... |
| CVE-2025-11188 | HIGH | 7.3 | 0.3% | Oct 10, 2025 | The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued... |
| CVE-2025-52634 | HIGH | 7.5 | 0.2% | Oct 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0. |
| CVE-2025-52632 | HIGH | 7.5 | 0.1% | Oct 10, 2025 | A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0. |
| CVE-2025-52630 | HIGH | 7.5 | 0.2% | Oct 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0. |
| CVE-2025-30001 | HIGH | 7.3 | 0.5% | Oct 10, 2025 | Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now