2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20149 | MEDIUM | 6.5 | 0.1% | Sep 24, 2025 | A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker ... |
| CVE-2025-20365 | MEDIUM | 4.3 | 0.2% | Sep 24, 2025 | A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an un... |
| CVE-2025-20364 | MEDIUM | 4.3 | 0.1% | Sep 24, 2025 | A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow... |
| CVE-2025-20339 | MEDIUM | 5.8 | 0.3% | Sep 24, 2025 | A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow a... |
| CVE-2025-27036 | MEDIUM | 6.1 | 0.1% | Sep 24, 2025 | Information disclosure when Video engine escape input data is less than expected minimum size. |
| CVE-2025-27033 | MEDIUM | 6.1 | 0.1% | Sep 24, 2025 | Information disclosure while running video usecase having rogue firmware. |
| CVE-2025-27030 | MEDIUM | 6.1 | 0.1% | Sep 24, 2025 | information disclosure while invoking calibration data from user space to update firmware size. |
| CVE-2025-10360 | MEDIUM | 6.9 | 0.2% | Sep 24, 2025 | In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant... |
| CVE-2025-8869 | MEDIUM | 5.9 | 0.4% | Sep 24, 2025 | When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module... |
| CVE-2025-23338 | MEDIUM | 5.5 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write... |
| CVE-2025-23274 | MEDIUM | 4.5 | 0.1% | Sep 24, 2025 | NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a mali... |
| CVE-2025-23273 | MEDIUM | 4.7 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a di... |
| CVE-2025-23272 | MEDIUM | 5.7 | 0.1% | Sep 24, 2025 | NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially... |
| CVE-2025-9353 | MEDIUM | 6.4 | 0.3% | Sep 24, 2025 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers... |
| CVE-2025-60020 | MEDIUM | 6.4 | 0.2% | Sep 24, 2025 | nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in p... |
| CVE-2025-39890 | MEDIUM | 5.5 | 0.1% | Sep 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_rea... |
| CVE-2025-39889 | MEDIUM | 5.5 | 0.1% | Sep 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on inco... |
| CVE-2025-58457 | MEDIUM | 4.3 | 0.3% | Sep 24, 2025 | Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insu... |
| CVE-2025-9031 | MEDIUM | 4.3 | 0.2% | Sep 24, 2025 | Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Doma... |
| CVE-2025-41716 | MEDIUM | 5.3 | 0.4% | Sep 24, 2025 | The web application allows an unauthenticated remote attacker to learn information about existing user accounts with the... |
| CVE-2025-48459 | MEDIUM | 5.3 | 0.5% | Sep 24, 2025 | Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0... |
| CVE-2025-43819 | MEDIUM | 6.5 | 0.2% | Sep 24, 2025 | A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.... |
| CVE-2025-43779 | MEDIUM | 6.1 | 0.2% | Sep 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024... |
| CVE-2025-58069 | MEDIUM | 6.9 | 0.2% | Sep 23, 2025 | The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerabili... |
| CVE-2025-54855 | MEDIUM | 4.2 | 0.1% | Sep 23, 2025 | Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now