2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23345 | MEDIUM | 4.4 | 0.1% | Oct 23, 2025 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause a... |
| CVE-2025-23332 | MEDIUM | 5 | 0.1% | Oct 23, 2025 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger ... |
| CVE-2025-23330 | MEDIUM | 5.5 | 0.2% | Oct 23, 2025 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer deref... |
| CVE-2025-23300 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer d... |
| CVE-2025-11621 | HIGH | 8.1 | 0.5% | Oct 23, 2025 | Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the co... |
| CVE-2025-10937 | MEDIUM | 6.8 | 0.2% | Oct 23, 2025 | Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local ... |
| CVE-2025-61464 | MEDIUM | 6.5 | 0.2% | Oct 23, 2025 | gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.ph... |
| CVE-2025-61413 | MEDIUM | 6.1 | 0.3% | Oct 23, 2025 | A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers ... |
| CVE-2025-57240 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute ar... |
| CVE-2025-62713 | HIGH | 7.2 | 0.7% | Oct 23, 2025 | Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authenticati... |
| CVE-2025-34156 | MEDIUM | 6.9 | 0.3% | Oct 23, 2025 | Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /c... |
| CVE-2025-34155 | MEDIUM | 6.9 | 0.6% | Oct 23, 2025 | Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authen... |
| CVE-2025-62169 | HIGH | 8.1 | 0.4% | Oct 23, 2025 | OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of th... |
| CVE-2025-59048 | HIGH | 8.1 | 0.2% | Oct 23, 2025 | OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is v... |
| CVE-2025-50951 | MEDIUM | 6.5 | 0.2% | Oct 23, 2025 | FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c. |
| CVE-2025-50950 | HIGH | 7.5 | 0.3% | Oct 23, 2025 | Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function. |
| CVE-2025-50949 | MEDIUM | 6.5 | 0.2% | Oct 23, 2025 | FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8. |
| CVE-2025-12114 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue af... |
| CVE-2025-61136 | HIGH | 7.1 | 0.4% | Oct 23, 2025 | A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attack... |
| CVE-2025-61132 | HIGH | 7.1 | 0.3% | Oct 23, 2025 | A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attacker... |
| CVE-2025-56009 | MEDIUM | 5.3 | 0.2% | Oct 23, 2025 | Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take... |
| CVE-2025-56008 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near t... |
| CVE-2025-56007 | MEDIUM | 6.5 | 0.3% | Oct 23, 2025 | CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding addi... |
| CVE-2025-12110 | MEDIUM | 5.4 | 0.3% | Oct 23, 2025 | A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the... |
| CVE-2025-62256 | MEDIUM | 5.3 | 0.4% | Oct 23, 2025 | Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now