2025 CVE Vulnerabilities
45,208 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59503 | CRITICAL | 9.8 | 0.7% | Oct 23, 2025 | Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a... |
| CVE-2025-59500 | HIGH | 8.8 | 0.5% | Oct 23, 2025 | Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network... |
| CVE-2025-59273 | CRITICAL | 9.8 | 0.3% | Oct 23, 2025 | Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-58456 | HIGH | 8.2 | 0.6% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab... |
| CVE-2025-58078 | HIGH | 8.3 | 0.6% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnera... |
| CVE-2025-12100 | HIGH | 8.8 | 0.1% | Oct 23, 2025 | Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue a... |
| CVE-2025-62517 | MEDIUM | 5.9 | 0.4% | Oct 23, 2025 | Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1... |
| CVE-2025-62236 | MEDIUM | 6.9 | 0.3% | Oct 23, 2025 | The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with ... |
| CVE-2025-58428 | CRITICAL | 9.9 | 1.3% | Oct 23, 2025 | The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. Thi... |
| CVE-2025-57848 | MEDIUM | 6.4 | 0.2% | Oct 23, 2025 | A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from... |
| CVE-2025-55067 | HIGH | 7.1 | 0.4% | Oct 23, 2025 | The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When th... |
| CVE-2025-54966 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return s... |
| CVE-2025-54964 | HIGH | 8.4 | 0.3% | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi... |
| CVE-2025-54963 | MEDIUM | 6.5 | 0.6% | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi... |
| CVE-2025-12044 | HIGH | 7.5 | 0.5% | Oct 23, 2025 | Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payload... |
| CVE-2025-6980 | HIGH | 7.5 | 0.4% | Oct 23, 2025 | Captive Portal can expose sensitive information |
| CVE-2025-6979 | HIGH | 8.8 | 0.5% | Oct 23, 2025 | Captive Portal can allow authentication bypass |
| CVE-2025-6978 | HIGH | 7.2 | 11.7% | Oct 23, 2025 | Diagnostics command injection vulnerability |
| CVE-2025-62255 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.... |
| CVE-2025-60859 | MEDIUM | 6.1 | 0.3% | Oct 23, 2025 | Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via... |
| CVE-2025-60837 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in ... |
| CVE-2025-54808 | HIGH | 7.8 | 0.2% | Oct 23, 2025 | Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file locat... |
| CVE-2025-23352 | HIGH | 7.8 | 0.2% | Oct 23, 2025 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitiali... |
| CVE-2025-23347 | HIGH | 7.8 | 0.1% | Oct 23, 2025 | NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful e... |
| CVE-2025-23345 | MEDIUM | 4.4 | 0.1% | Oct 23, 2025 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now