2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20315 | HIGH | 8.6 | 0.4% | Sep 24, 2025 | A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unau... |
| CVE-2025-20312 | HIGH | 7.7 | 0.4% | Sep 24, 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe... |
| CVE-2025-20311 | HIGH | 7.4 | 0.2% | Sep 24, 2025 | A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches co... |
| CVE-2025-20160 | HIGH | 8.1 | 0.4% | Sep 24, 2025 | A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allo... |
| CVE-2025-56816 | HIGH | 8.8 | 1.3% | Sep 24, 2025 | Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attack... |
| CVE-2025-56815 | HIGH | 7.1 | 0.6% | Sep 24, 2025 | Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses ... |
| CVE-2025-20334 | HIGH | 8.8 | 0.5% | Sep 24, 2025 | A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that... |
| CVE-2025-10892 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-10891 | HIGH | 8.8 | 6.6% | Sep 24, 2025 | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-10502 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit ... |
| CVE-2025-10501 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap ... |
| CVE-2025-10500 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-47329 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while handling invalid inputs in application info setup. |
| CVE-2025-47328 | HIGH | 7.5 | 0.2% | Sep 24, 2025 | Transient DOS while processing power control requests with invalid antenna or stream values. |
| CVE-2025-47327 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while encoding the image data. |
| CVE-2025-47326 | HIGH | 7.5 | 0.2% | Sep 24, 2025 | Transient DOS while handling command data during power control processing. |
| CVE-2025-47318 | HIGH | 7.5 | 0.2% | Sep 24, 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. |
| CVE-2025-47317 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption due to global buffer overflow when a test command uses an invalid payload type. |
| CVE-2025-47316 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption due to double free when multiple threads race to set the timestamp store. |
| CVE-2025-47315 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while handling repeated memory unmap requests from guest VM. |
| CVE-2025-47314 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while processing data sent by FE driver. |
| CVE-2025-27077 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while processing message in guest VM. |
| CVE-2025-27037 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers. |
| CVE-2025-27032 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache ... |
| CVE-2025-21488 | HIGH | 8.2 | 0.2% | Sep 24, 2025 | Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is se... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now