2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-43943MEDIUM6.7Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used ...
CVE-2025-33116MEDIUM5.4IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allo...
CVE-2025-26333HIGH7.5Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated ...
CVE-2025-20363CRITICAL9A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Fi...
CVE-2025-20362HIGH8.6Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Softwar...
CVE-2025-20333CRITICAL9.9A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu...
CVE-2025-10953HIGH8.8A security vulnerability has been detected in UTT 1200GW and 1250GW up to 3.0.0-170831/3.2.2-200710. This vulnerability ...
CVE-2025-10952MEDIUM5.5A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this...
CVE-2025-10911MEDIUM5.5A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired ...
CVE-2025-59838MEDIUM5.4Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user inpu...
CVE-2025-59832CRITICAL9.9Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS...
CVE-2025-59830HIGH7.5Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only f...
CVE-2025-59823CRITICAL9.9Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection m...
CVE-2025-55551HIGH7.5An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when per...
CVE-2025-46153MEDIUM5.3PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency wit...
CVE-2025-46152MEDIUM5.3In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" a...
CVE-2025-46150MEDIUM5.3In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.
CVE-2025-46149MEDIUM5.3In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.
CVE-2025-46148MEDIUM5.3In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.
CVE-2025-40838HIGH7.5Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if ...
CVE-2025-40837HIGH8.8Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the s...
CVE-2025-40836CRITICAL9.8Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacke...
CVE-2025-36857LOW3.3Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's conf...
CVE-2025-36601HIGH7.5Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthoriz...
CVE-2025-27262HIGH7.8Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now