2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56241 | HIGH | 7.5 | 6.3% | Sep 24, 2025 | Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the ... |
| CVE-2025-52907 | HIGH | 8.8 | 0.9% | Sep 24, 2025 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affect... |
| CVE-2025-48869 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded res... |
| CVE-2025-20352 | HIGH | 7.7 | 39.4% | Sep 24, 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa... |
| CVE-2025-20327 | HIGH | 7.7 | 0.4% | Sep 24, 2025 | A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to... |
| CVE-2025-20315 | HIGH | 8.6 | — | Sep 24, 2025 | A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unau... |
| CVE-2025-20312 | HIGH | 7.7 | 0.4% | Sep 24, 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe... |
| CVE-2025-20311 | HIGH | 7.4 | 0.2% | Sep 24, 2025 | A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches co... |
| CVE-2025-20160 | HIGH | 8.1 | 0.4% | Sep 24, 2025 | A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allo... |
| CVE-2025-56816 | HIGH | 8.8 | 1.3% | Sep 24, 2025 | Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attack... |
| CVE-2025-56815 | HIGH | 7.1 | 0.6% | Sep 24, 2025 | Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses ... |
| CVE-2025-20334 | HIGH | 8.8 | 0.5% | Sep 24, 2025 | A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that... |
| CVE-2025-10892 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-10891 | HIGH | 8.8 | 6.9% | Sep 24, 2025 | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-10502 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit ... |
| CVE-2025-10501 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap ... |
| CVE-2025-10500 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-47329 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while handling invalid inputs in application info setup. |
| CVE-2025-47328 | HIGH | 7.5 | 0.2% | Sep 24, 2025 | Transient DOS while processing power control requests with invalid antenna or stream values. |
| CVE-2025-47327 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while encoding the image data. |
| CVE-2025-47326 | HIGH | 7.5 | 0.2% | Sep 24, 2025 | Transient DOS while handling command data during power control processing. |
| CVE-2025-47318 | HIGH | 7.5 | 0.2% | Sep 24, 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. |
| CVE-2025-47317 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption due to global buffer overflow when a test command uses an invalid payload type. |
| CVE-2025-47316 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption due to double free when multiple threads race to set the timestamp store. |
| CVE-2025-47315 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while handling repeated memory unmap requests from guest VM. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now