2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62654 | LOW | 2 | 0.3% | Oct 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62653 | LOW | 2 | 0.3% | Oct 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62505 | LOW | 3 | 0.3% | Oct 17, 2025 | LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-... |
| CVE-2025-60361 | LOW | 3.3 | 0.1% | Oct 17, 2025 | radare2 v5.9.8 and before contains a memory leak in the function bochs_open. |
| CVE-2025-11896 | LOW | 2.1 | 0.2% | Oct 16, 2025 | In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stac... |
| CVE-2025-61924 | LOW | 3.8 | 0.2% | Oct 16, 2025 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and... |
| CVE-2025-11851 | LOW | 3.5 | 0.3% | Oct 16, 2025 | A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set... |
| CVE-2025-54499 | LOW | 3.7 | 0.2% | Oct 16, 2025 | Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comp... |
| CVE-2025-62380 | LOW | 2.9 | 0.4% | Oct 15, 2025 | mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr... |
| CVE-2025-62379 | LOW | 3.1 | 0.2% | Oct 15, 2025 | Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace e... |
| CVE-2025-2529 | LOW | 3.7 | 0.2% | Oct 15, 2025 | Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application u... |
| CVE-2025-6026 | LOW | 3.1 | 0.1% | Oct 15, 2025 | An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could all... |
| CVE-2025-56746 | LOW | 2.2 | 0.2% | Oct 15, 2025 | Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabli... |
| CVE-2025-59280 | LOW | 3.1 | 0.4% | Oct 14, 2025 | Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. |
| CVE-2025-55695 | LOW | 3.3 | 0.4% | Oct 14, 2025 | Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally. |
| CVE-2025-62366 | LOW | 2.9 | 0.4% | Oct 14, 2025 | mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr... |
| CVE-2025-8594 | LOW | 3.8 | 0.2% | Oct 14, 2025 | The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could a... |
| CVE-2025-11731 | LOW | 3.1 | 0.3% | Oct 14, 2025 | A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during sty... |
| CVE-2025-42909 | LOW | 3 | 0.2% | Oct 14, 2025 | SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default p... |
| CVE-2025-62174 | LOW | 3.5 | 0.2% | Oct 13, 2025 | Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.2... |
| CVE-2025-39964 | LOW | 3.3 | 0.2% | Oct 13, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_a... |
| CVE-2025-31995 | LOW | 3.5 | 0.5% | Oct 13, 2025 | HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities ... |
| CVE-2025-11645 | LOW | 2.4 | 0.2% | Oct 12, 2025 | A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown... |
| CVE-2025-11637 | LOW | 3.7 | 0.3% | Oct 12, 2025 | A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036. Impacted is an unknown function of the component ... |
| CVE-2025-2139 | LOW | 3.5 | 0.2% | Oct 12, 2025 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the networ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now