2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59429 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior t... |
| CVE-2025-33177 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could all... |
| CVE-2025-54275 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could lead to... |
| CVE-2025-8459 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-60537 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows a... |
| CVE-2025-57563 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to rea... |
| CVE-2025-8430 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-59497 | MEDIUM | 4.7 | 0.2% | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny ... |
| CVE-2025-59294 | MEDIUM | 4.6 | 0.6% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to di... |
| CVE-2025-59288 | MEDIUM | 5.3 | 0.2% | Oct 14, 2025 | Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofi... |
| CVE-2025-59284 | MEDIUM | 5.5 | 0.9% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp... |
| CVE-2025-59260 | MEDIUM | 5.5 | 0.4% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an author... |
| CVE-2025-59259 | MEDIUM | 6.5 | 1.4% | Oct 14, 2025 | Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d... |
| CVE-2025-59258 | MEDIUM | 6.2 | 0.5% | Oct 14, 2025 | Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker... |
| CVE-2025-59257 | MEDIUM | 6.5 | 1.4% | Oct 14, 2025 | Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d... |
| CVE-2025-59253 | MEDIUM | 5.5 | 0.3% | Oct 14, 2025 | Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. |
| CVE-2025-59244 | MEDIUM | 6.5 | 0.7% | Oct 14, 2025 | External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n... |
| CVE-2025-59229 | MEDIUM | 5.5 | 0.4% | Oct 14, 2025 | Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally. |
| CVE-2025-59214 | MEDIUM | 6.5 | 1.8% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p... |
| CVE-2025-59211 | MEDIUM | 5.5 | 0.6% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attack... |
| CVE-2025-59209 | MEDIUM | 5.5 | 0.4% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attack... |
| CVE-2025-59204 | MEDIUM | 5.5 | 0.5% | Oct 14, 2025 | Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information local... |
| CVE-2025-59203 | MEDIUM | 5.5 | 0.4% | Oct 14, 2025 | Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclos... |
| CVE-2025-59198 | MEDIUM | 5 | 0.4% | Oct 14, 2025 | Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. |
| CVE-2025-59197 | MEDIUM | 5.5 | 0.4% | Oct 14, 2025 | Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose inform... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now