2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11568 | MEDIUM | 4.4 | 0.1% | Oct 15, 2025 | A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption for... |
| CVE-2025-62378 | MEDIUM | 6.1 | 0.1% | Oct 15, 2025 | CommandKit is the discord.js meta-framework for building Discord bots. In versions 1.2.0-rc.1 through 1.2.0-rc.11, a log... |
| CVE-2025-58132 | MEDIUM | 6.5 | 1.9% | Oct 15, 2025 | Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of informatio... |
| CVE-2025-54271 | MEDIUM | 5.6 | 0.1% | Oct 15, 2025 | Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Conditio... |
| CVE-2025-20360 | MEDIUM | 5.8 | 0.4% | Oct 15, 2025 | Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,... |
| CVE-2025-20359 | MEDIUM | 6.5 | 0.4% | Oct 15, 2025 | Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,... |
| CVE-2025-20351 | MEDIUM | 6.1 | 0.3% | Oct 15, 2025 | A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon... |
| CVE-2025-20329 | MEDIUM | 4.9 | 0.3% | Oct 15, 2025 | A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software cou... |
| CVE-2025-61933 | MEDIUM | 6.1 | 0.2% | Oct 15, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker... |
| CVE-2025-59419 | MEDIUM | 5.5 | 1.6% | Oct 15, 2025 | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final... |
| CVE-2025-53860 | MEDIUM | 4.1 | 0.1% | Oct 15, 2025 | A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIP... |
| CVE-2025-9548 | MEDIUM | 6.8 | 0.1% | Oct 15, 2025 | A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a... |
| CVE-2025-56748 | MEDIUM | 6.4 | 0.2% | Oct 15, 2025 | Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templat... |
| CVE-2025-55083 | MEDIUM | 5.3 | 0.2% | Oct 15, 2025 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check result... |
| CVE-2025-10699 | MEDIUM | 6 | 0.2% | Oct 15, 2025 | A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow inform... |
| CVE-2025-60015 | MEDIUM | 6.9 | 0.2% | Oct 15, 2025 | An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption. Note: Softw... |
| CVE-2025-60013 | MEDIUM | 4.6 | 0.2% | Oct 15, 2025 | When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with sp... |
| CVE-2025-59483 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which hav... |
| CVE-2025-59268 | MEDIUM | 6.9 | 0.4% | Oct 15, 2025 | On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthent... |
| CVE-2025-58474 | MEDIUM | 5.3 | 0.4% | Oct 15, 2025 | When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an... |
| CVE-2025-58424 | MEDIUM | 6.3 | 0.2% | Oct 15, 2025 | On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which d... |
| CVE-2025-58153 | MEDIUM | 5.9 | 0.2% | Oct 15, 2025 | Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-S... |
| CVE-2025-54805 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can ... |
| CVE-2025-54755 | MEDIUM | 4.9 | 1.1% | Oct 15, 2025 | A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access file... |
| CVE-2025-9640 | MEDIUM | 4.3 | 0.4% | Oct 15, 2025 | A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into altern... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now