2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57354 | MEDIUM | 6.5 | 0.5% | Sep 24, 2025 | A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user... |
| CVE-2025-57353 | MEDIUM | 5.3 | 0.3% | Sep 24, 2025 | The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Du... |
| CVE-2025-57352 | MEDIUM | 5.3 | 0.3% | Sep 24, 2025 | A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespa... |
| CVE-2025-48867 | MEDIUM | 4.8 | 0.2% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerabi... |
| CVE-2025-20338 | MEDIUM | 6.7 | 0.2% | Sep 24, 2025 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri... |
| CVE-2025-20316 | MEDIUM | 5.3 | 0.3% | Sep 24, 2025 | A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X... |
| CVE-2025-20314 | MEDIUM | 6.7 | 0.2% | Sep 24, 2025 | A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an una... |
| CVE-2025-20313 | MEDIUM | 6.7 | 0.2% | Sep 24, 2025 | Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileg... |
| CVE-2025-20293 | MEDIUM | 5.3 | 0.2% | Sep 24, 2025 | A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for ... |
| CVE-2025-20240 | MEDIUM | 6.1 | 0.3% | Sep 24, 2025 | A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attack... |
| CVE-2025-20149 | MEDIUM | 6.5 | 0.1% | Sep 24, 2025 | A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker ... |
| CVE-2025-20365 | MEDIUM | 4.3 | 0.2% | Sep 24, 2025 | A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an un... |
| CVE-2025-20364 | MEDIUM | 4.3 | 0.1% | Sep 24, 2025 | A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow... |
| CVE-2025-20339 | MEDIUM | 5.8 | 0.3% | Sep 24, 2025 | A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow a... |
| CVE-2025-27036 | MEDIUM | 6.1 | 0.1% | Sep 24, 2025 | Information disclosure when Video engine escape input data is less than expected minimum size. |
| CVE-2025-27033 | MEDIUM | 6.1 | 0.1% | Sep 24, 2025 | Information disclosure while running video usecase having rogue firmware. |
| CVE-2025-27030 | MEDIUM | 6.1 | 0.1% | Sep 24, 2025 | information disclosure while invoking calibration data from user space to update firmware size. |
| CVE-2025-10360 | MEDIUM | 6.9 | 0.2% | Sep 24, 2025 | In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant... |
| CVE-2025-8869 | MEDIUM | 5.9 | 0.5% | Sep 24, 2025 | When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module... |
| CVE-2025-23338 | MEDIUM | 5.5 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write... |
| CVE-2025-23274 | MEDIUM | 4.5 | 0.1% | Sep 24, 2025 | NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a mali... |
| CVE-2025-23273 | MEDIUM | 4.7 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a di... |
| CVE-2025-23272 | MEDIUM | 5.7 | 0.2% | Sep 24, 2025 | NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially... |
| CVE-2025-9353 | MEDIUM | 6.4 | 0.3% | Sep 24, 2025 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers... |
| CVE-2025-60020 | MEDIUM | 6.4 | 0.2% | Sep 24, 2025 | nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now