2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43943 | MEDIUM | 6.7 | 0.5% | Sep 25, 2025 | Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used ... |
| CVE-2025-33116 | MEDIUM | 5.4 | 0.2% | Sep 25, 2025 | IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allo... |
| CVE-2025-26333 | HIGH | 7.5 | 0.3% | Sep 25, 2025 | Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated ... |
| CVE-2025-20363 | CRITICAL | 9 | 7.5% | Sep 25, 2025 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Fi... |
| CVE-2025-20362 | HIGH | 8.6 | 85.5% | Sep 25, 2025 | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar... |
| CVE-2025-20333 | CRITICAL | 9.9 | 40.4% | Sep 25, 2025 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu... |
| CVE-2025-10953 | HIGH | 8.8 | 4.4% | Sep 25, 2025 | A security vulnerability has been detected in UTT 1200GW and 1250GW up to 3.0.0-170831/3.2.2-200710. This vulnerability ... |
| CVE-2025-10952 | MEDIUM | 5.5 | 0.3% | Sep 25, 2025 | A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this... |
| CVE-2025-10911 | MEDIUM | 5.5 | 0.2% | Sep 25, 2025 | A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired ... |
| CVE-2025-59838 | MEDIUM | 5.4 | 0.2% | Sep 25, 2025 | Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user inpu... |
| CVE-2025-59832 | CRITICAL | 9.9 | 0.4% | Sep 25, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS... |
| CVE-2025-59830 | HIGH | 7.5 | 0.5% | Sep 25, 2025 | Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only f... |
| CVE-2025-59823 | CRITICAL | 9.9 | 0.5% | Sep 25, 2025 | Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection m... |
| CVE-2025-55551 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when per... |
| CVE-2025-46153 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency wit... |
| CVE-2025-46152 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" a... |
| CVE-2025-46150 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results. |
| CVE-2025-46149 | MEDIUM | 5.3 | 0.3% | Sep 25, 2025 | In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error. |
| CVE-2025-46148 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results. |
| CVE-2025-40838 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if ... |
| CVE-2025-40837 | HIGH | 8.8 | 0.3% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the s... |
| CVE-2025-40836 | CRITICAL | 9.8 | 0.4% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacke... |
| CVE-2025-36857 | LOW | 3.3 | 0.1% | Sep 25, 2025 | Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's conf... |
| CVE-2025-36601 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthoriz... |
| CVE-2025-27262 | HIGH | 7.8 | 0.8% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now