2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22891 | HIGH | 8.7 | 0.4% | Feb 5, 2025 | When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic ... |
| CVE-2025-22846 | HIGH | 8.7 | 0.4% | Feb 5, 2025 | When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic ca... |
| CVE-2025-21091 | HIGH | 8.7 | 0.4% | Feb 5, 2025 | When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilizatio... |
| CVE-2025-21087 | HIGH | 8.9 | 0.4% | Feb 5, 2025 | When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclo... |
| CVE-2025-20058 | HIGH | 8.9 | 0.4% | Feb 5, 2025 | When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in me... |
| CVE-2025-20045 | HIGH | 8.7 | 0.4% | Feb 5, 2025 | When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are ... |
| CVE-2025-20029 | HIGH | 8.8 | 7.8% | Feb 5, 2025 | Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an au... |
| CVE-2025-20184 | HIGH | 7.2 | 0.9% | Feb 5, 2025 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco... |
| CVE-2025-20176 | HIGH | 7.7 | 0.7% | Feb 5, 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo... |
| CVE-2025-20175 | HIGH | 7.7 | 0.7% | Feb 5, 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo... |
| CVE-2025-20174 | HIGH | 7.7 | 0.7% | Feb 5, 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo... |
| CVE-2025-20173 | HIGH | 7.7 | 0.7% | Feb 5, 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo... |
| CVE-2025-20172 | HIGH | 7.7 | 0.7% | Feb 5, 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allo... |
| CVE-2025-20171 | HIGH | 7.7 | 0.7% | Feb 5, 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo... |
| CVE-2025-20170 | HIGH | 7.7 | 0.7% | Feb 5, 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo... |
| CVE-2025-20169 | HIGH | 7.7 | 0.7% | Feb 5, 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo... |
| CVE-2025-20125 | HIGH | 7.2 | 14.5% | Feb 5, 2025 | A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to... |
| CVE-2025-20124 | HIGH | 7.2 | 16.3% | Feb 5, 2025 | A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as th... |
| CVE-2025-0725 | HIGH | 7.3 | 1.2% | Feb 5, 2025 | When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT... |
| CVE-2025-0665 | HIGH | 7 | 1.2% | Feb 5, 2025 | libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having co... |
| CVE-2025-25246 | HIGH | 8.1 | 0.7% | Feb 5, 2025 | NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unau... |
| CVE-2025-1026 | HIGH | 8.6 | 0.5% | Feb 5, 2025 | Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL ... |
| CVE-2025-1025 | HIGH | 7.7 | 17.6% | Feb 5, 2025 | Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can us... |
| CVE-2025-1022 | HIGH | 8.2 | 0.4% | Feb 5, 2025 | Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml funct... |
| CVE-2025-1028 | HIGH | 8.1 | 0.7% | Feb 5, 2025 | The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now