2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40645 | HIGH | 8.7 | 0.3% | Oct 2, 2025 | Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensiti... |
| CVE-2025-9587 | HIGH | 8.6 | 0.3% | Oct 2, 2025 | The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before usin... |
| CVE-2025-61692 | HIGH | 7.8 | 0.1% | Oct 2, 2025 | VT STUDIO versions 8.53 and prior contain a use after free vulnerability. If the product uses a specially crafted file, ... |
| CVE-2025-61691 | HIGH | 7.8 | 0.1% | Oct 2, 2025 | VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability. If the product uses a specially crafted f... |
| CVE-2025-61690 | HIGH | 7.8 | 0.1% | Oct 2, 2025 | KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted fil... |
| CVE-2025-58777 | HIGH | 7.8 | 0.1% | Oct 2, 2025 | VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specia... |
| CVE-2025-58776 | HIGH | 8.4 | 0.2% | Oct 2, 2025 | KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially ... |
| CVE-2025-58775 | HIGH | 8.4 | 0.2% | Oct 2, 2025 | KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted... |
| CVE-2025-11182 | HIGH | 7.1 | 0.4% | Oct 2, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check... |
| CVE-2025-11020 | HIGH | 8.8 | 0.3% | Oct 2, 2025 | An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly ex... |
| CVE-2025-61582 | HIGH | 7.5 | 0.4% | Oct 1, 2025 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been ident... |
| CVE-2025-54811 | HIGH | 7.1 | 0.2% | Oct 1, 2025 | OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value. This leads to a... |
| CVE-2025-23355 | HIGH | 7.8 | 0.1% | Oct 1, 2025 | NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL hi... |
| CVE-2025-23297 | HIGH | 7.8 | 0.1% | Oct 1, 2025 | NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attac... |
| CVE-2025-59538 | HIGH | 7.5 | 0.5% | Oct 1, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-... |
| CVE-2025-59537 | HIGH | 7.5 | 0.6% | Oct 1, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 throug... |
| CVE-2025-59531 | HIGH | 7.5 | 0.5% | Oct 1, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 throug... |
| CVE-2025-59150 | HIGH | 7.5 | 0.5% | Oct 1, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-59148 | HIGH | 7.5 | 0.4% | Oct 1, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-59147 | HIGH | 7.5 | 0.3% | Oct 1, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-56588 | HIGH | 8.8 | 0.5% | Oct 1, 2025 | Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module con... |
| CVE-2025-46205 | HIGH | 8.1 | 0.4% | Oct 1, 2025 | A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to caus... |
| CVE-2025-10578 | HIGH | 7.8 | 0.1% | Oct 1, 2025 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The ... |
| CVE-2025-60991 | HIGH | 8.8 | 0.4% | Oct 1, 2025 | A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to exe... |
| CVE-2025-57393 | HIGH | 8.8 | 0.3% | Oct 1, 2025 | A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2val... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now