2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20312HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe...
CVE-2025-20311HIGH7.4A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches co...
CVE-2025-20293MEDIUM5.3A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for ...
CVE-2025-20240MEDIUM6.1A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attack...
CVE-2025-20160HIGH8.1A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allo...
CVE-2025-20149MEDIUM6.5A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker ...
CVE-2025-56816HIGH8.8Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attack...
CVE-2025-56815HIGH7.1Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses ...
CVE-2025-20365MEDIUM4.3A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an un...
CVE-2025-20364MEDIUM4.3A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow...
CVE-2025-20339MEDIUM5.8A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow a...
CVE-2025-20334HIGH8.8A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that...
CVE-2025-10909LOW2.4A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the f...
CVE-2025-10892HIGH8.8Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co...
CVE-2025-10891HIGH8.8Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co...
CVE-2025-10890CRITICAL9.1Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-...
CVE-2025-10585CRITICAL9.8Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-10502HIGH8.8Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit ...
CVE-2025-10501HIGH8.8Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap ...
CVE-2025-10500HIGH8.8Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co...
CVE-2025-56819CRITICAL9.8An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
CVE-2025-47329HIGH7.8Memory corruption while handling invalid inputs in application info setup.
CVE-2025-47328HIGH7.5Transient DOS while processing power control requests with invalid antenna or stream values.
CVE-2025-47327HIGH7.8Memory corruption while encoding the image data.
CVE-2025-47326HIGH7.5Transient DOS while handling command data during power control processing.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now