2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11203 | LOW | 3.5 | 0.4% | Oct 29, 2025 | LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to d... |
| CVE-2025-56558 | LOW | 3 | 0.4% | Oct 29, 2025 | The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct v... |
| CVE-2025-62794 | LOW | 3.8 | 0.1% | Oct 28, 2025 | GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced s... |
| CVE-2025-10939 | LOW | 3.7 | 0.4% | Oct 28, 2025 | A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the install... |
| CVE-2025-12251 | LOW | 3.5 | 0.2% | Oct 27, 2025 | A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI.... |
| CVE-2025-12224 | LOW | 3.5 | 0.2% | Oct 27, 2025 | A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerabili... |
| CVE-2025-11888 | LOW | 2.7 | 0.2% | Oct 25, 2025 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable ... |
| CVE-2025-11244 | LOW | 3.7 | 0.3% | Oct 25, 2025 | The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all version... |
| CVE-2025-62711 | LOW | 3.1 | 0.4% | Oct 24, 2025 | Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model r... |
| CVE-2025-10723 | LOW | 2.7 | 0.3% | Oct 24, 2025 | The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate pa... |
| CVE-2025-62659 | LOW | 2.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-41721 | LOW | 2.7 | 0.2% | Oct 22, 2025 | A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralizat... |
| CVE-2025-62774 | LOW | 3.1 | 0.2% | Oct 22, 2025 | On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps. |
| CVE-2025-62773 | LOW | 2.4 | 0.2% | Oct 22, 2025 | Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator. |
| CVE-2025-62772 | LOW | 3.1 | 0.1% | Oct 22, 2025 | On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases. |
| CVE-2025-62480 | LOW | 2.7 | 0.3% | Oct 21, 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The sup... |
| CVE-2025-62479 | LOW | 2.7 | 0.3% | Oct 21, 2025 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The suppor... |
| CVE-2025-61755 | LOW | 3.7 | 0.2% | Oct 21, 2025 | Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). Supported versions that ar... |
| CVE-2025-61749 | LOW | 2.7 | 0.2% | Oct 21, 2025 | Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-2... |
| CVE-2025-61748 | LOW | 3.7 | 0.4% | Oct 21, 2025 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2025-53051 | LOW | 2.7 | 0.3% | Oct 21, 2025 | Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected a... |
| CVE-2025-5496 | LOW | 3.3 | 0.2% | Oct 21, 2025 | ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected b... |
| CVE-2025-57837 | LOW | 2.9 | 0.2% | Oct 20, 2025 | Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affe... |
| CVE-2025-11945 | LOW | 3.5 | 0.3% | Oct 19, 2025 | A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the compo... |
| CVE-2025-62655 | LOW | 2.1 | 0.2% | Oct 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foun... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now