2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61857 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlie... |
| CVE-2025-61856 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earl... |
| CVE-2025-52625 | HIGH | 7.5 | 0.2% | Oct 10, 2025 | A vulnerability Cacheable SSL Page Found vulnerability has been identified in HCL AION. Cached data may expose cre... |
| CVE-2025-11189 | HIGH | 7.3 | 0.4% | Oct 10, 2025 | The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, ... |
| CVE-2025-11188 | HIGH | 7.3 | 0.3% | Oct 10, 2025 | The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued... |
| CVE-2025-52634 | HIGH | 7.5 | 0.2% | Oct 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0. |
| CVE-2025-52632 | HIGH | 7.5 | 0.1% | Oct 10, 2025 | A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0. |
| CVE-2025-52630 | HIGH | 7.5 | 0.2% | Oct 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0. |
| CVE-2025-30001 | HIGH | 7.3 | 0.5% | Oct 10, 2025 | Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from... |
| CVE-2025-21069 | HIGH | 7.1 | 0.1% | Oct 10, 2025 | Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to ac... |
| CVE-2025-21068 | HIGH | 7.1 | 0.1% | Oct 10, 2025 | Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to ac... |
| CVE-2025-21067 | HIGH | 7.1 | 0.1% | Oct 10, 2025 | Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers ... |
| CVE-2025-21066 | HIGH | 7.1 | 0.1% | Oct 10, 2025 | Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-o... |
| CVE-2025-21062 | HIGH | 7.8 | 0.1% | Oct 10, 2025 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to rep... |
| CVE-2025-21058 | HIGH | 7.3 | 0.1% | Oct 10, 2025 | Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attack... |
| CVE-2025-21055 | HIGH | 7.5 | 0.3% | Oct 10, 2025 | Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access... |
| CVE-2025-21053 | HIGH | 7.8 | 0.1% | Oct 10, 2025 | Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local a... |
| CVE-2025-21052 | HIGH | 7.8 | 0.1% | Oct 10, 2025 | Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 ... |
| CVE-2025-21051 | HIGH | 7.8 | 0.1% | Oct 10, 2025 | Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local at... |
| CVE-2025-21048 | HIGH | 7.8 | 0.2% | Oct 10, 2025 | Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary c... |
| CVE-2025-61871 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the w... |
| CVE-2025-61779 | HIGH | 8.7 | 0.3% | Oct 9, 2025 | Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing ... |
| CVE-2025-61773 | HIGH | 8.1 | 0.4% | Oct 9, 2025 | pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web inte... |
| CVE-2025-61602 | HIGH | 7.5 | 0.4% | Oct 9, 2025 | BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 a... |
| CVE-2025-61601 | HIGH | 7.5 | 0.4% | Oct 9, 2025 | BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now