2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20312 | HIGH | 7.7 | 0.4% | Sep 24, 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe... |
| CVE-2025-20311 | HIGH | 7.4 | 0.2% | Sep 24, 2025 | A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches co... |
| CVE-2025-20293 | MEDIUM | 5.3 | 0.2% | Sep 24, 2025 | A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for ... |
| CVE-2025-20240 | MEDIUM | 6.1 | 0.3% | Sep 24, 2025 | A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attack... |
| CVE-2025-20160 | HIGH | 8.1 | 0.4% | Sep 24, 2025 | A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allo... |
| CVE-2025-20149 | MEDIUM | 6.5 | 0.1% | Sep 24, 2025 | A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker ... |
| CVE-2025-56816 | HIGH | 8.8 | 1.3% | Sep 24, 2025 | Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attack... |
| CVE-2025-56815 | HIGH | 7.1 | 0.6% | Sep 24, 2025 | Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses ... |
| CVE-2025-20365 | MEDIUM | 4.3 | 0.2% | Sep 24, 2025 | A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an un... |
| CVE-2025-20364 | MEDIUM | 4.3 | 0.1% | Sep 24, 2025 | A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow... |
| CVE-2025-20339 | MEDIUM | 5.8 | 0.3% | Sep 24, 2025 | A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow a... |
| CVE-2025-20334 | HIGH | 8.8 | 0.5% | Sep 24, 2025 | A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that... |
| CVE-2025-10909 | LOW | 2.4 | 0.3% | Sep 24, 2025 | A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the f... |
| CVE-2025-10892 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-10891 | HIGH | 8.8 | 6.6% | Sep 24, 2025 | Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-10890 | CRITICAL | 9.1 | 0.3% | Sep 24, 2025 | Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-... |
| CVE-2025-10585 | CRITICAL | 9.8 | 5.4% | Sep 24, 2025 | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2025-10502 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit ... |
| CVE-2025-10501 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap ... |
| CVE-2025-10500 | HIGH | 8.8 | 0.3% | Sep 24, 2025 | Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co... |
| CVE-2025-56819 | CRITICAL | 9.8 | 3.0% | Sep 24, 2025 | An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter. |
| CVE-2025-47329 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while handling invalid inputs in application info setup. |
| CVE-2025-47328 | HIGH | 7.5 | 0.2% | Sep 24, 2025 | Transient DOS while processing power control requests with invalid antenna or stream values. |
| CVE-2025-47327 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while encoding the image data. |
| CVE-2025-47326 | HIGH | 7.5 | 0.2% | Sep 24, 2025 | Transient DOS while handling command data during power control processing. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now