2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21487 | HIGH | 8.2 | 0.2% | Sep 24, 2025 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is great... |
| CVE-2025-21484 | HIGH | 8.2 | 0.2% | Sep 24, 2025 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments f... |
| CVE-2025-21482 | HIGH | 7.1 | 0.1% | Sep 24, 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2025-21481 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while performing private key encryption in trusted application. |
| CVE-2025-21476 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake. |
| CVE-2025-48868 | HIGH | 7.2 | 2.3% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) ... |
| CVE-2025-23354 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data crea... |
| CVE-2025-23353 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data crea... |
| CVE-2025-23349 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an a... |
| CVE-2025-23348 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created b... |
| CVE-2025-23339 | HIGH | 7.8 | 0.3% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based bu... |
| CVE-2025-23308 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buff... |
| CVE-2025-23275 | HIGH | 7.1 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GP... |
| CVE-2025-10906 | HIGH | 8.4 | 0.2% | Sep 24, 2025 | A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:Wit... |
| CVE-2025-48392 | HIGH | 7.5 | 0.6% | Sep 24, 2025 | A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0... |
| CVE-2025-58319 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att... |
| CVE-2025-58317 | HIGH | 7.8 | 0.3% | Sep 24, 2025 | Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att... |
| CVE-2025-58473 | HIGH | 8.2 | 0.3% | Sep 23, 2025 | An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f... |
| CVE-2025-57882 | HIGH | 8.2 | 0.3% | Sep 23, 2025 | An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f... |
| CVE-2025-55069 | HIGH | 8.7 | 0.3% | Sep 23, 2025 | A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the C... |
| CVE-2025-55038 | HIGH | 7.6 | 0.2% | Sep 23, 2025 | An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Thro... |
| CVE-2025-59484 | HIGH | 8.7 | 0.1% | Sep 23, 2025 | The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The ... |
| CVE-2025-59826 | HIGH | 7.6 | 0.2% | Sep 23, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, pote... |
| CVE-2025-59822 | HIGH | 7.5 | 0.3% | Sep 23, 2025 | Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s ... |
| CVE-2025-59534 | HIGH | 7.8 | 0.9% | Sep 23, 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now