2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61924 | LOW | 3.8 | 0.2% | Oct 16, 2025 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and... |
| CVE-2025-11851 | LOW | 3.5 | 0.3% | Oct 16, 2025 | A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set... |
| CVE-2025-54499 | LOW | 3.7 | 0.2% | Oct 16, 2025 | Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comp... |
| CVE-2025-62380 | LOW | 2.9 | 0.4% | Oct 15, 2025 | mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr... |
| CVE-2025-62379 | LOW | 3.1 | 0.2% | Oct 15, 2025 | Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace e... |
| CVE-2025-2529 | LOW | 3.7 | 0.2% | Oct 15, 2025 | Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application u... |
| CVE-2025-6026 | LOW | 3.1 | 0.1% | Oct 15, 2025 | An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could all... |
| CVE-2025-56746 | LOW | 2.2 | 0.2% | Oct 15, 2025 | Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabli... |
| CVE-2025-59280 | LOW | 3.1 | 0.4% | Oct 14, 2025 | Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. |
| CVE-2025-55695 | LOW | 3.3 | 0.4% | Oct 14, 2025 | Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally. |
| CVE-2025-62366 | LOW | 2.9 | 0.4% | Oct 14, 2025 | mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr... |
| CVE-2025-8594 | LOW | 3.8 | 0.2% | Oct 14, 2025 | The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could a... |
| CVE-2025-11731 | LOW | 3.1 | 0.3% | Oct 14, 2025 | A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during sty... |
| CVE-2025-42909 | LOW | 3 | 0.2% | Oct 14, 2025 | SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default p... |
| CVE-2025-62174 | LOW | 3.5 | 0.2% | Oct 13, 2025 | Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.2... |
| CVE-2025-31995 | LOW | 3.5 | 0.5% | Oct 13, 2025 | HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities ... |
| CVE-2025-11645 | LOW | 2.4 | 0.2% | Oct 12, 2025 | A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown... |
| CVE-2025-11637 | LOW | 3.7 | 0.3% | Oct 12, 2025 | A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036. Impacted is an unknown function of the component ... |
| CVE-2025-2139 | LOW | 3.5 | 0.2% | Oct 12, 2025 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the networ... |
| CVE-2025-2138 | LOW | 3.5 | 0.2% | Oct 12, 2025 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the netw... |
| CVE-2025-8606 | LOW | 2.4 | 0.1% | Oct 11, 2025 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less ... |
| CVE-2025-52655 | LOW | 3.1 | 0.2% | Oct 10, 2025 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-part... |
| CVE-2025-21057 | LOW | 3.3 | 0.1% | Oct 10, 2025 | Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to... |
| CVE-2025-21046 | LOW | 2.4 | 0.1% | Oct 10, 2025 | Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to tem... |
| CVE-2025-4614 | LOW | 2.7 | 0.2% | Oct 9, 2025 | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now