2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-55559HIGH7.5An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras....
CVE-2025-55558HIGH7.5A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshr...
CVE-2025-55557HIGH7.5A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading...
CVE-2025-55553HIGH7.5A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
CVE-2025-55552HIGH7.5pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are us...
CVE-2025-26333HIGH7.5Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated ...
CVE-2025-20362HIGH8.6Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar...
CVE-2025-10953HIGH8.8A security vulnerability has been detected in UTT 1200GW and 1250GW up to 3.0.0-170831/3.2.2-200710. This vulnerability ...
CVE-2025-59830HIGH7.5Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only f...
CVE-2025-55551HIGH7.5An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when per...
CVE-2025-40838HIGH7.5Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if ...
CVE-2025-40837HIGH8.8Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the s...
CVE-2025-36601HIGH7.5Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthoriz...
CVE-2025-27262HIGH7.8Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation o...
CVE-2025-10951HIGH7.3A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vuln...
CVE-2025-10541HIGH7.8iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This serv...
CVE-2025-5494HIGH7.8ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This ...
CVE-2025-59831HIGH8.8git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, ...
CVE-2025-57317HIGH7.5apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulner...
CVE-2025-26278HIGH7.5A prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via sup...
CVE-2025-10948HIGH8.8A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip...
CVE-2025-10467HIGH8.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Comp...
CVE-2025-10449HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems ...
CVE-2025-40698HIGH8.7SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve,...
CVE-2025-10957HIGH8.7This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now