2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22406 | HIGH | 8.4 | 0.1% | Aug 26, 2025 | In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. ... |
| CVE-2025-22405 | HIGH | 8.4 | 0.1% | Aug 26, 2025 | In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc... |
| CVE-2025-22404 | HIGH | 8.4 | 0.1% | Aug 26, 2025 | In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This ... |
| CVE-2025-0093 | HIGH | 7.5 | 0.3% | Aug 26, 2025 | In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission... |
| CVE-2025-0084 | HIGH | 8.8 | 0.2% | Aug 26, 2025 | In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code e... |
| CVE-2025-0081 | HIGH | 7.5 | 0.4% | Aug 26, 2025 | In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitiali... |
| CVE-2025-0080 | HIGH | 7.8 | 0.1% | Aug 26, 2025 | In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overl... |
| CVE-2025-0079 | HIGH | 7.8 | 0.1% | Aug 26, 2025 | In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error i... |
| CVE-2025-0078 | HIGH | 8.8 | 0.3% | Aug 26, 2025 | In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to loca... |
| CVE-2025-50971 | HIGH | 7.5 | 0.9% | Aug 26, 2025 | Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensiti... |
| CVE-2025-9478 | HIGH | 8.8 | 3.6% | Aug 26, 2025 | Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap c... |
| CVE-2025-23315 | HIGH | 7.8 | 0.2% | Aug 26, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious dat... |
| CVE-2025-23314 | HIGH | 7.8 | 0.2% | Aug 26, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a... |
| CVE-2025-23313 | HIGH | 7.8 | 0.2% | Aug 26, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a... |
| CVE-2025-23312 | HIGH | 7.8 | 0.2% | Aug 26, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious da... |
| CVE-2025-23307 | HIGH | 7.8 | 0.3% | Aug 26, 2025 | NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow... |
| CVE-2025-57803 | HIGH | 8.8 | 0.8% | Aug 26, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2025-55298 | HIGH | 8.8 | 4.1% | Aug 26, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick vers... |
| CVE-2025-9491 | HIGH | 7.8 | 63.1% | Aug 26, 2025 | Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote at... |
| CVE-2025-55212 | HIGH | 7.5 | 0.9% | Aug 26, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2025-36729 | HIGH | 7.2 | 0.4% | Aug 26, 2025 | A non-primary administrator user with admin rights to the web interface but without shell access permissions can display... |
| CVE-2025-1994 | HIGH | 7.8 | 0.1% | Aug 26, 2025 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due t... |
| CVE-2025-57810 | HIGH | 7.5 | 0.7% | Aug 26, 2025 | jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage me... |
| CVE-2025-6366 | HIGH | 8.8 | 0.3% | Aug 26, 2025 | The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. T... |
| CVE-2025-52218 | HIGH | 7.5 | 0.3% | Aug 26, 2025 | SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sani... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now