2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55559 | HIGH | 7.5 | 0.2% | Sep 25, 2025 | An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.... |
| CVE-2025-55558 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshr... |
| CVE-2025-55557 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading... |
| CVE-2025-55553 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS). |
| CVE-2025-55552 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are us... |
| CVE-2025-26333 | HIGH | 7.5 | 0.3% | Sep 25, 2025 | Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated ... |
| CVE-2025-20362 | HIGH | 8.6 | 85.5% | Sep 25, 2025 | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar... |
| CVE-2025-10953 | HIGH | 8.8 | 4.4% | Sep 25, 2025 | A security vulnerability has been detected in UTT 1200GW and 1250GW up to 3.0.0-170831/3.2.2-200710. This vulnerability ... |
| CVE-2025-59830 | HIGH | 7.5 | 0.5% | Sep 25, 2025 | Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only f... |
| CVE-2025-55551 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when per... |
| CVE-2025-40838 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if ... |
| CVE-2025-40837 | HIGH | 8.8 | 0.3% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the s... |
| CVE-2025-36601 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthoriz... |
| CVE-2025-27262 | HIGH | 7.8 | 0.8% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation o... |
| CVE-2025-10951 | HIGH | 7.3 | 0.6% | Sep 25, 2025 | A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vuln... |
| CVE-2025-10541 | HIGH | 7.8 | 0.2% | Sep 25, 2025 | iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This serv... |
| CVE-2025-5494 | HIGH | 7.8 | 0.3% | Sep 25, 2025 | ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This ... |
| CVE-2025-59831 | HIGH | 8.8 | 2.3% | Sep 25, 2025 | git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, ... |
| CVE-2025-57317 | HIGH | 7.5 | 0.3% | Sep 25, 2025 | apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulner... |
| CVE-2025-26278 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | A prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via sup... |
| CVE-2025-10948 | HIGH | 8.8 | 0.7% | Sep 25, 2025 | A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip... |
| CVE-2025-10467 | HIGH | 8.9 | 0.3% | Sep 25, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Comp... |
| CVE-2025-10449 | HIGH | 8.6 | 0.4% | Sep 25, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems ... |
| CVE-2025-40698 | HIGH | 8.7 | 0.2% | Sep 25, 2025 | SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve,... |
| CVE-2025-10957 | HIGH | 8.7 | 0.3% | Sep 25, 2025 | This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now