2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-47318HIGH7.5Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-47317HIGH7.8Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
CVE-2025-47316HIGH7.8Memory corruption due to double free when multiple threads race to set the timestamp store.
CVE-2025-47315HIGH7.8Memory corruption while handling repeated memory unmap requests from guest VM.
CVE-2025-47314HIGH7.8Memory corruption while processing data sent by FE driver.
CVE-2025-27077HIGH7.8Memory corruption while processing message in guest VM.
CVE-2025-27037HIGH7.8Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.
CVE-2025-27036MEDIUM6.1Information disclosure when Video engine escape input data is less than expected minimum size.
CVE-2025-27034CRITICAL9.8Memory corruption while selecting the PLMN from SOR failed list.
CVE-2025-27033MEDIUM6.1Information disclosure while running video usecase having rogue firmware.
CVE-2025-27032HIGH7.8memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache ...
CVE-2025-27030MEDIUM6.1information disclosure while invoking calibration data from user space to update firmware size.
CVE-2025-21488HIGH8.2Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is se...
CVE-2025-21487HIGH8.2Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is great...
CVE-2025-21484HIGH8.2Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments f...
CVE-2025-21483CRITICAL9.8Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-21482HIGH7.1Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-21481HIGH7.8Memory corruption while performing private key encryption in trusted application.
CVE-2025-21476HIGH7.8Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.
CVE-2025-10360MEDIUM6.9In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant...
CVE-2025-8869MEDIUM5.9When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module...
CVE-2025-48868HIGH7.2Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) ...
CVE-2025-23354HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data crea...
CVE-2025-23353HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data crea...
CVE-2025-23349HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now