2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28357 | HIGH | 8.8 | 0.4% | Oct 1, 2025 | A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supp... |
| CVE-2025-20371 | HIGH | 8.8 | 0.4% | Oct 1, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.10... |
| CVE-2025-56515 | HIGH | 8.8 | 0.5% | Oct 1, 2025 | File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fail... |
| CVE-2025-59684 | HIGH | 8.8 | 0.5% | Oct 1, 2025 | DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking. |
| CVE-2025-52042 | HIGH | 8.2 | 0.3% | Oct 1, 2025 | In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/re... |
| CVE-2025-52041 | HIGH | 8.2 | 0.3% | Oct 1, 2025 | In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reco... |
| CVE-2025-52040 | HIGH | 8.2 | 0.3% | Oct 1, 2025 | In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Inje... |
| CVE-2025-52039 | HIGH | 8.2 | 0.3% | Oct 1, 2025 | In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_requ... |
| CVE-2025-10847 | HIGH | 8.4 | 0.4% | Oct 1, 2025 | DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robo... |
| CVE-2025-39922 | HIGH | 7.1 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix incorrect map used in eee linkmode inco... |
| CVE-2025-39917 | HIGH | 7.8 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds dynptr write in bpf_crypto_c... |
| CVE-2025-39913 | HIGH | 7.8 | 0.2% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdi... |
| CVE-2025-39911 | HIGH | 7.8 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: i40e: fix IRQ freeing in i40e_vsi_request_irq_msix ... |
| CVE-2025-39905 | HIGH | 7 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: phylink: add lock for serializing concurrent p... |
| CVE-2025-39901 | HIGH | 7.1 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'com... |
| CVE-2025-39896 | HIGH | 7.8 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued... |
| CVE-2025-39891 | HIGH | 7.1 | 0.2% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Initialize the chan_stats array to z... |
| CVE-2025-11226 | HIGH | 7 | 0.2% | Oct 1, 2025 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.1... |
| CVE-2025-10538 | HIGH | 8.8 | 0.6% | Oct 1, 2025 | An authentication bypass vulnerability exists in LG Innotek camera models LND7210 and LNV7210R. The vulnerability allows... |
| CVE-2025-24525 | HIGH | 8.7 | 0.2% | Sep 30, 2025 | Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or dec... |
| CVE-2025-56392 | HIGH | 8.1 | 0.3% | Sep 30, 2025 | An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attack... |
| CVE-2025-56132 | HIGH | 7.3 | 0.6% | Sep 30, 2025 | LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The appli... |
| CVE-2025-23293 | HIGH | 8.7 | 0.2% | Sep 30, 2025 | NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause... |
| CVE-2025-6034 | HIGH | 8.5 | 0.2% | Sep 30, 2025 | There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor ... |
| CVE-2025-6033 | HIGH | 8.5 | 0.2% | Sep 30, 2025 | There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in N... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now