2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47314 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while processing data sent by FE driver. |
| CVE-2025-27077 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while processing message in guest VM. |
| CVE-2025-27037 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers. |
| CVE-2025-27032 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache ... |
| CVE-2025-21488 | HIGH | 8.2 | 0.3% | Sep 24, 2025 | Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is se... |
| CVE-2025-21487 | HIGH | 8.2 | 0.3% | Sep 24, 2025 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is great... |
| CVE-2025-21484 | HIGH | 8.2 | 0.3% | Sep 24, 2025 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments f... |
| CVE-2025-21482 | HIGH | 7.1 | 0.1% | Sep 24, 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2025-21481 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while performing private key encryption in trusted application. |
| CVE-2025-21476 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake. |
| CVE-2025-48868 | HIGH | 7.2 | 2.5% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) ... |
| CVE-2025-23354 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data crea... |
| CVE-2025-23353 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data crea... |
| CVE-2025-23349 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an a... |
| CVE-2025-23348 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created b... |
| CVE-2025-23339 | HIGH | 7.8 | 0.4% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based bu... |
| CVE-2025-23308 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buff... |
| CVE-2025-23275 | HIGH | 7.1 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GP... |
| CVE-2025-10906 | HIGH | 8.4 | 0.2% | Sep 24, 2025 | A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:Wit... |
| CVE-2025-48392 | HIGH | 7.5 | 0.6% | Sep 24, 2025 | A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0... |
| CVE-2025-58319 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att... |
| CVE-2025-58317 | HIGH | 7.8 | 0.3% | Sep 24, 2025 | Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att... |
| CVE-2025-58473 | HIGH | 8.2 | 0.3% | Sep 23, 2025 | An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f... |
| CVE-2025-57882 | HIGH | 8.2 | 0.3% | Sep 23, 2025 | An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f... |
| CVE-2025-55069 | HIGH | 8.7 | 0.3% | Sep 23, 2025 | A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the C... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now