2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20329MEDIUM4.9A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software cou...
CVE-2025-10577HIGH8.5Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research ...
CVE-2025-10576HIGH8.5Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research ...
CVE-2025-62379LOW3.1Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace e...
CVE-2025-62370HIGH7.5Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered ...
CVE-2025-61990HIGH8.7When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microk...
CVE-2025-61935HIGH8.7When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the ...
CVE-2025-61933MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker...
CVE-2025-59419MEDIUM5.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final...
CVE-2025-58071HIGH8.7When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to...
CVE-2025-57780HIGH8.8A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalat...
CVE-2025-53860MEDIUM4.1A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIP...
CVE-2025-2529LOW3.7Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application u...
CVE-2025-9548MEDIUM6.8A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a...
CVE-2025-8486HIGH8.5A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with el...
CVE-2025-6026LOW3.1An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could all...
CVE-2025-56749CRITICAL9.4Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictabl...
CVE-2025-56748MEDIUM6.4Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templat...
CVE-2025-55083MEDIUM5.3In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check result...
CVE-2025-10699MEDIUM6A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow inform...
CVE-2025-10581HIGH8.5A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment t...
CVE-2025-61974HIGH8.7When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resour...
CVE-2025-61960HIGH8.7When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the ...
CVE-2025-61958HIGH8.7A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administ...
CVE-2025-61955HIGH8.8A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escala...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now