2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10963 | HIGH | 8.8 | 6.8% | Sep 25, 2025 | A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. Affected is the function sub_4016F0 of the file /c... |
| CVE-2025-10962 | HIGH | 8.8 | 6.8% | Sep 25, 2025 | A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This impacts the function sub_403198 of the file /cgi-b... |
| CVE-2025-60249 | MEDIUM | 6.4 | 0.2% | Sep 25, 2025 | vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and user.py, by a user on a vulnerability-lookup instan... |
| CVE-2025-57623 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Servi... |
| CVE-2025-48707 | HIGH | 7.5 | 0.3% | Sep 25, 2025 | An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in som... |
| CVE-2025-29155 | MEDIUM | 6.5 | 0.4% | Sep 25, 2025 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint |
| CVE-2025-10961 | HIGH | 8 | 8.1% | Sep 25, 2025 | A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. This affects the function sub_4030C0 of the file /cgi-b... |
| CVE-2025-10960 | HIGH | 8.8 | 6.8% | Sep 25, 2025 | A vulnerability was found in Wavlink NU516U1 M16U1_V240425. The impacted element is the function sub_402D1C of the file ... |
| CVE-2025-10959 | HIGH | 8.8 | 6.6% | Sep 25, 2025 | A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. The affected element is the function sub_401778 of the ... |
| CVE-2025-10958 | HIGH | 8.8 | 6.8% | Sep 25, 2025 | A flaw has been found in Wavlink NU516U1 M16U1_V240425. Impacted is the function sub_403010 of the file /cgi-bin/wireles... |
| CVE-2025-34227 | HIGH | 8.8 | 25.9% | Sep 25, 2025 | Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL ... |
| CVE-2025-10880 | HIGH | 7.5 | 0.3% | Sep 25, 2025 | All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allo... |
| CVE-2025-10879 | MEDIUM | 5.3 | 0.3% | Sep 25, 2025 | All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allo... |
| CVE-2025-60019 | LOW | 3.7 | 0.3% | Sep 25, 2025 | glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memo... |
| CVE-2025-60018 | MEDIUM | 4.8 | 0.3% | Sep 25, 2025 | glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out... |
| CVE-2025-59841 | CRITICAL | 9.8 | 0.4% | Sep 25, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application i... |
| CVE-2025-57446 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote attackers to cause a deni... |
| CVE-2025-55560 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse... |
| CVE-2025-55559 | HIGH | 7.5 | 0.2% | Sep 25, 2025 | An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.... |
| CVE-2025-55558 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshr... |
| CVE-2025-55557 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading... |
| CVE-2025-55556 | MEDIUM | 6.5 | 0.2% | Sep 25, 2025 | TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in t... |
| CVE-2025-55554 | MEDIUM | 5.3 | 0.3% | Sep 25, 2025 | pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long(). |
| CVE-2025-55553 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS). |
| CVE-2025-55552 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are us... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now