2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47318 | HIGH | 7.5 | 0.2% | Sep 24, 2025 | Transient DOS while parsing the EPTM test control message to get the test pattern. |
| CVE-2025-47317 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption due to global buffer overflow when a test command uses an invalid payload type. |
| CVE-2025-47316 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption due to double free when multiple threads race to set the timestamp store. |
| CVE-2025-47315 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while handling repeated memory unmap requests from guest VM. |
| CVE-2025-47314 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while processing data sent by FE driver. |
| CVE-2025-27077 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while processing message in guest VM. |
| CVE-2025-27037 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers. |
| CVE-2025-27036 | MEDIUM | 6.1 | 0.1% | Sep 24, 2025 | Information disclosure when Video engine escape input data is less than expected minimum size. |
| CVE-2025-27034 | CRITICAL | 9.8 | 0.4% | Sep 24, 2025 | Memory corruption while selecting the PLMN from SOR failed list. |
| CVE-2025-27033 | MEDIUM | 6.1 | 0.1% | Sep 24, 2025 | Information disclosure while running video usecase having rogue firmware. |
| CVE-2025-27032 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache ... |
| CVE-2025-27030 | MEDIUM | 6.1 | 0.1% | Sep 24, 2025 | information disclosure while invoking calibration data from user space to update firmware size. |
| CVE-2025-21488 | HIGH | 8.2 | 0.2% | Sep 24, 2025 | Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is se... |
| CVE-2025-21487 | HIGH | 8.2 | 0.2% | Sep 24, 2025 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is great... |
| CVE-2025-21484 | HIGH | 8.2 | 0.2% | Sep 24, 2025 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments f... |
| CVE-2025-21483 | CRITICAL | 9.8 | 0.4% | Sep 24, 2025 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. |
| CVE-2025-21482 | HIGH | 7.1 | 0.1% | Sep 24, 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2025-21481 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption while performing private key encryption in trusted application. |
| CVE-2025-21476 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake. |
| CVE-2025-10360 | MEDIUM | 6.9 | 0.2% | Sep 24, 2025 | In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant... |
| CVE-2025-8869 | MEDIUM | 5.9 | 0.4% | Sep 24, 2025 | When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module... |
| CVE-2025-48868 | HIGH | 7.2 | 2.3% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) ... |
| CVE-2025-23354 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data crea... |
| CVE-2025-23353 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data crea... |
| CVE-2025-23349 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now