2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57638 | HIGH | 7.5 | 0.4% | Sep 23, 2025 | Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value. |
| CVE-2025-57637 | HIGH | 7.5 | 0.6% | Sep 23, 2025 | Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav... |
| CVE-2025-54081 | HIGH | 7 | 0.2% | Sep 23, 2025 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineS... |
| CVE-2025-51005 | HIGH | 7.5 | 0.4% | Sep 23, 2025 | A heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file ... |
| CVE-2025-8410 | HIGH | 7.4 | 0.2% | Sep 23, 2025 | Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.This issue affects ... |
| CVE-2025-56394 | HIGH | 7.5 | 0.4% | Sep 23, 2025 | Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slic... |
| CVE-2025-55780 | HIGH | 7.5 | 0.4% | Sep 23, 2025 | A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malfor... |
| CVE-2025-52905 | HIGH | 7.5 | 7.8% | Sep 23, 2025 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1... |
| CVE-2025-4582 | HIGH | 7.1 | 0.1% | Sep 23, 2025 | Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, ... |
| CVE-2025-9900 | HIGH | 8.8 | 0.7% | Sep 23, 2025 | A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes ... |
| CVE-2025-5717 | HIGH | 7.2 | 0.6% | Sep 23, 2025 | An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input valida... |
| CVE-2025-9844 | HIGH | 8.8 | 0.4% | Sep 23, 2025 | Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable... |
| CVE-2025-8354 | HIGH | 7.8 | 0.2% | Sep 23, 2025 | A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A maliciou... |
| CVE-2025-6921 | HIGH | 7.5 | 0.5% | Sep 23, 2025 | The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (R... |
| CVE-2025-10184 | HIGH | 8.2 | 3.7% | Sep 23, 2025 | The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provi... |
| CVE-2025-9966 | HIGH | 7.3 | 0.3% | Sep 23, 2025 | Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service ... |
| CVE-2025-9964 | HIGH | 8.6 | 0.2% | Sep 23, 2025 | No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. T... |
| CVE-2025-10244 | HIGH | 8.7 | 0.4% | Sep 23, 2025 | A maliciously crafted HTML payload, when rendered by the Autodesk Fusion desktop application, can trigger a Stored Cross... |
| CVE-2025-9798 | HIGH | 8.9 | 0.3% | Sep 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Soft... |
| CVE-2025-10848 | HIGH | 8.8 | 0.4% | Sep 23, 2025 | A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown p... |
| CVE-2025-10846 | HIGH | 8.8 | 0.4% | Sep 23, 2025 | A vulnerability was determined in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /m... |
| CVE-2025-10845 | HIGH | 8.8 | 0.4% | Sep 23, 2025 | A vulnerability was found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Componente... |
| CVE-2025-10844 | HIGH | 8.8 | 0.4% | Sep 23, 2025 | A vulnerability has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality o... |
| CVE-2025-39888 | HIGH | 7.8 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: fuse: Block access to folio overlimit syz reported... |
| CVE-2025-39883 | HIGH | 7.1 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now