2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-41399HIGH8.7When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can c...
CVE-2025-36557HIGH8.7When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can ...
CVE-2025-36525HIGH8.7When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to termin...
CVE-2025-36504HIGH8.7When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase i...
CVE-2025-35995HIGH8.7When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the url...
CVE-2025-31644HIGH8.7When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS...
CVE-2025-3925HIGH8.5BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution...
CVE-2025-30147HIGH8.7Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum cli...
CVE-2025-26169HIGH8.1IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from...
CVE-2025-26168HIGH8.1IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code executio...
CVE-2025-32821HIGH7.2A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges ...
CVE-2025-32820HIGH8.8A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal...
CVE-2025-32819HIGH8.8A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversa...
CVE-2025-20210HIGH7.3A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticate...
CVE-2025-20202HIGH7.4A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause ...
CVE-2025-20200HIGH8.2A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15...
CVE-2025-20199HIGH8.2A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15...
CVE-2025-20198HIGH8.2A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15...
CVE-2025-20197HIGH8.2A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15...
CVE-2025-20192HIGH7.7A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an au...
CVE-2025-20191HIGH7.4A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX...
CVE-2025-20189HIGH7.4A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Ser...
CVE-2025-20186HIGH8.8A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software co...
CVE-2025-20182HIGH8.6A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance ...
CVE-2025-20164HIGH8.3A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authent...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now