2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41399 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can c... |
| CVE-2025-36557 | HIGH | 8.7 | 0.4% | May 7, 2025 | When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can ... |
| CVE-2025-36525 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to termin... |
| CVE-2025-36504 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase i... |
| CVE-2025-35995 | HIGH | 8.7 | 0.4% | May 7, 2025 | When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the url... |
| CVE-2025-31644 | HIGH | 8.7 | 26.1% | May 7, 2025 | When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS... |
| CVE-2025-3925 | HIGH | 8.5 | 0.2% | May 7, 2025 | BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution... |
| CVE-2025-30147 | HIGH | 8.7 | 0.2% | May 7, 2025 | Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum cli... |
| CVE-2025-26169 | HIGH | 8.1 | 0.2% | May 7, 2025 | IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from... |
| CVE-2025-26168 | HIGH | 8.1 | 0.2% | May 7, 2025 | IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code executio... |
| CVE-2025-32821 | HIGH | 7.2 | 29.4% | May 7, 2025 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges ... |
| CVE-2025-32820 | HIGH | 8.8 | 3.0% | May 7, 2025 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal... |
| CVE-2025-32819 | HIGH | 8.8 | 6.8% | May 7, 2025 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversa... |
| CVE-2025-20210 | HIGH | 7.3 | 0.3% | May 7, 2025 | A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticate... |
| CVE-2025-20202 | HIGH | 7.4 | 0.2% | May 7, 2025 | A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause ... |
| CVE-2025-20200 | HIGH | 8.2 | 0.1% | May 7, 2025 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15... |
| CVE-2025-20199 | HIGH | 8.2 | 0.1% | May 7, 2025 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15... |
| CVE-2025-20198 | HIGH | 8.2 | 0.1% | May 7, 2025 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15... |
| CVE-2025-20197 | HIGH | 8.2 | 0.1% | May 7, 2025 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15... |
| CVE-2025-20192 | HIGH | 7.7 | 0.4% | May 7, 2025 | A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an au... |
| CVE-2025-20191 | HIGH | 7.4 | 0.2% | May 7, 2025 | A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX... |
| CVE-2025-20189 | HIGH | 7.4 | 0.2% | May 7, 2025 | A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Ser... |
| CVE-2025-20186 | HIGH | 8.8 | 1.2% | May 7, 2025 | A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software co... |
| CVE-2025-20182 | HIGH | 8.6 | 0.5% | May 7, 2025 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance ... |
| CVE-2025-20164 | HIGH | 8.3 | 0.3% | May 7, 2025 | A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authent... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now