2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54276 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Substance3D - Modeler versions 1.22.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a cra... |
| CVE-2025-34267 | CRITICAL | 9.9 | 6.1% | Oct 14, 2025 | Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code exec... |
| CVE-2025-33177 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could all... |
| CVE-2025-54280 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-54275 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could lead to... |
| CVE-2025-54274 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Substance3D - Viewer versions 0.25.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could ... |
| CVE-2025-54273 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-33182 | HIGH | 7.6 | 0.3% | Oct 14, 2025 | NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause... |
| CVE-2025-8459 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-60537 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows a... |
| CVE-2025-60536 | HIGH | 7.5 | 0.6% | Oct 14, 2025 | An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Servi... |
| CVE-2025-57618 | HIGH | 7.3 | 0.7% | Oct 14, 2025 | A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the s... |
| CVE-2025-57563 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to rea... |
| CVE-2025-23356 | HIGH | 8.4 | 0.1% | Oct 14, 2025 | NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might... |
| CVE-2025-11736 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionalit... |
| CVE-2025-8430 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-60535 | HIGH | 7.3 | 0.2% | Oct 14, 2025 | A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to e... |
| CVE-2025-59502 | HIGH | 7.5 | 1.0% | Oct 14, 2025 | Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over ... |
| CVE-2025-59497 | MEDIUM | 4.7 | 0.2% | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny ... |
| CVE-2025-59494 | HIGH | 7.8 | 0.6% | Oct 14, 2025 | Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59295 | HIGH | 8.8 | 1.8% | Oct 14, 2025 | Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. |
| CVE-2025-59294 | MEDIUM | 4.6 | 0.6% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to di... |
| CVE-2025-59292 | HIGH | 8.2 | 0.4% | Oct 14, 2025 | External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate... |
| CVE-2025-59291 | HIGH | 8.2 | 0.4% | Oct 14, 2025 | External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate... |
| CVE-2025-59290 | HIGH | 7.8 | 0.4% | Oct 14, 2025 | Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now