2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26482 | MEDIUM | 4.9 | 0.3% | Sep 25, 2025 | Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privi... |
| CVE-2025-10965 | MEDIUM | 6.3 | 0.3% | Sep 25, 2025 | A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyll... |
| CVE-2025-29157 | MEDIUM | 6.5 | 0.5% | Sep 25, 2025 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/ca... |
| CVE-2025-29156 | MEDIUM | 6.1 | 0.4% | Sep 25, 2025 | Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted ... |
| CVE-2025-60249 | MEDIUM | 6.4 | 0.2% | Sep 25, 2025 | vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and user.py, by a user on a vulnerability-lookup instan... |
| CVE-2025-57623 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Servi... |
| CVE-2025-29155 | MEDIUM | 6.5 | 0.4% | Sep 25, 2025 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint |
| CVE-2025-10879 | MEDIUM | 5.3 | 0.3% | Sep 25, 2025 | All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allo... |
| CVE-2025-60018 | MEDIUM | 4.8 | 0.3% | Sep 25, 2025 | glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out... |
| CVE-2025-55556 | MEDIUM | 6.5 | 0.2% | Sep 25, 2025 | TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in t... |
| CVE-2025-55554 | MEDIUM | 5.3 | 0.3% | Sep 25, 2025 | pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). |
| CVE-2025-43943 | MEDIUM | 6.7 | 0.5% | Sep 25, 2025 | Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used ... |
| CVE-2025-33116 | MEDIUM | 5.4 | 0.2% | Sep 25, 2025 | IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allo... |
| CVE-2025-10952 | MEDIUM | 5.5 | 0.3% | Sep 25, 2025 | A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this... |
| CVE-2025-10911 | MEDIUM | 5.5 | 0.2% | Sep 25, 2025 | A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired ... |
| CVE-2025-59838 | MEDIUM | 5.4 | 0.2% | Sep 25, 2025 | Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user inpu... |
| CVE-2025-46153 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency wit... |
| CVE-2025-46152 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" a... |
| CVE-2025-46150 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results. |
| CVE-2025-46149 | MEDIUM | 5.3 | 0.3% | Sep 25, 2025 | In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error. |
| CVE-2025-46148 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results. |
| CVE-2025-10950 | MEDIUM | 6.3 | 0.3% | Sep 25, 2025 | A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the funct... |
| CVE-2025-59839 | MEDIUM | 5.4 | 0.3% | Sep 25, 2025 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em... |
| CVE-2025-59426 | MEDIUM | 4.3 | 0.3% | Sep 25, 2025 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirec... |
| CVE-2025-10540 | MEDIUM | 6.5 | 0.1% | Sep 25, 2025 | iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now