2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61724 | MEDIUM | 5.3 | 0.5% | Oct 29, 2025 | The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the n... |
| CVE-2025-61723 | HIGH | 7.5 | 0.6% | Oct 29, 2025 | The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affe... |
| CVE-2025-58189 | MEDIUM | 5.3 | 0.4% | Oct 29, 2025 | When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols... |
| CVE-2025-58188 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that as... |
| CVE-2025-58187 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with ... |
| CVE-2025-58186 | MEDIUM | 5.3 | 0.5% | Oct 29, 2025 | Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By s... |
| CVE-2025-58185 | MEDIUM | 5.3 | 0.5% | Oct 29, 2025 | Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion. |
| CVE-2025-58183 | MEDIUM | 4.3 | 0.4% | Oct 29, 2025 | tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A mal... |
| CVE-2025-54549 | MEDIUM | 5.9 | 0.1% | Oct 29, 2025 | Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgra... |
| CVE-2025-54548 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user... |
| CVE-2025-54547 | MEDIUM | 5.3 | 0.1% | Oct 29, 2025 | On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) mult... |
| CVE-2025-54546 | HIGH | 7.5 | 0.2% | Oct 29, 2025 | On affected platforms, restricted users could use SSH port forwarding to access host-internal services |
| CVE-2025-54545 | HIGH | 7.8 | 0.1% | Oct 29, 2025 | On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privil... |
| CVE-2025-47912 | MEDIUM | 5.3 | 0.4% | Oct 29, 2025 | The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component ... |
| CVE-2025-11428 | — | — | — | Oct 29, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-61959 | MEDIUM | 6.9 | 0.2% | Oct 29, 2025 | Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebR... |
| CVE-2025-54459 | HIGH | 8.7 | 0.4% | Oct 29, 2025 | Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd witho... |
| CVE-2025-9871 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local ... |
| CVE-2025-9870 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability all... |
| CVE-2025-9869 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local at... |
| CVE-2025-60320 | MEDIUM | 6.7 | 0.1% | Oct 29, 2025 | memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (... |
| CVE-2025-11466 | MEDIUM | 4.9 | 1.9% | Oct 29, 2025 | Allegra DatabaseBackupBL Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote atta... |
| CVE-2025-11465 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remot... |
| CVE-2025-11464 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2025-11463 | HIGH | 7.8 | 0.2% | Oct 29, 2025 | Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows rem... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now