2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20714 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20713 | HIGH | 7.8 | 0.1% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20712 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (... |
| CVE-2025-20711 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (... |
| CVE-2025-20710 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proxim... |
| CVE-2025-20709 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (... |
| CVE-2025-10228 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affect... |
| CVE-2025-46581 | CRITICAL | 9.8 | 0.7% | Oct 14, 2025 | ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can ... |
| CVE-2025-41718 | HIGH | 7.5 | 0.2% | Oct 14, 2025 | A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote a... |
| CVE-2025-41699 | HIGH | 8.8 | 0.9% | Oct 14, 2025 | An low privileged remote attacker with an account for the Web-based management can change the system configuration to pe... |
| CVE-2025-55078 | MEDIUM | 5.5 | 0.2% | Oct 14, 2025 | In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a r... |
| CVE-2025-41707 | MEDIUM | 5.3 | 1.4% | Oct 14, 2025 | The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a craf... |
| CVE-2025-41706 | MEDIUM | 5.3 | 1.7% | Oct 14, 2025 | The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET... |
| CVE-2025-41705 | MEDIUM | 6.8 | 0.4% | Oct 14, 2025 | An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials f... |
| CVE-2025-41704 | MEDIUM | 5.3 | 1.5% | Oct 14, 2025 | An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-functi... |
| CVE-2025-41703 | HIGH | 7.5 | 1.0% | Oct 14, 2025 | An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command... |
| CVE-2025-8594 | LOW | 3.8 | 0.2% | Oct 14, 2025 | The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could a... |
| CVE-2025-59889 | HIGH | 8.6 | 0.2% | Oct 14, 2025 | Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of a... |
| CVE-2025-11731 | LOW | 3.1 | 0.3% | Oct 14, 2025 | A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during sty... |
| CVE-2025-10732 | MEDIUM | 4.3 | 0.2% | Oct 14, 2025 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Dis... |
| CVE-2025-10357 | MEDIUM | 6.1 | 0.2% | Oct 14, 2025 | The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the pa... |
| CVE-2025-42939 | MEDIUM | 4.3 | 0.2% | Oct 14, 2025 | SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to de... |
| CVE-2025-42937 | CRITICAL | 9.8 | 0.7% | Oct 14, 2025 | SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated... |
| CVE-2025-42910 | CRITICAL | 9 | 0.4% | Oct 14, 2025 | Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attack... |
| CVE-2025-42909 | LOW | 3 | 0.2% | Oct 14, 2025 | SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now