2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2138 | LOW | 3.5 | 0.2% | Oct 12, 2025 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the netw... |
| CVE-2025-8606 | LOW | 2.4 | 0.1% | Oct 11, 2025 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less ... |
| CVE-2025-52655 | LOW | 3.1 | 0.2% | Oct 10, 2025 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-part... |
| CVE-2025-21057 | LOW | 3.3 | 0.1% | Oct 10, 2025 | Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to... |
| CVE-2025-21046 | LOW | 2.4 | 0.1% | Oct 10, 2025 | Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to tem... |
| CVE-2025-4614 | LOW | 2.7 | 0.2% | Oct 9, 2025 | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to... |
| CVE-2025-5009 | LOW | 1 | 0.1% | Oct 8, 2025 | In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire conversation via a sharable pub... |
| CVE-2025-11441 | LOW | 3.7 | 0.6% | Oct 8, 2025 | A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the compon... |
| CVE-2025-61786 | LOW | 3.3 | 0.2% | Oct 8, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype... |
| CVE-2025-61785 | LOW | 3.3 | 0.2% | Oct 8, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype... |
| CVE-2025-62187 | LOW | 3.3 | 0.2% | Oct 7, 2025 | In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations o... |
| CVE-2025-61670 | LOW | 3.3 | 0.2% | Oct 7, 2025 | Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings... |
| CVE-2025-59451 | LOW | 3.5 | 0.3% | Oct 6, 2025 | The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes. |
| CVE-2025-59447 | LOW | 2.2 | 0.2% | Oct 6, 2025 | The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can lev... |
| CVE-2025-61985 | LOW | 3.6 | 0.1% | Oct 6, 2025 | ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a Prox... |
| CVE-2025-61984 | LOW | 3.6 | 0.2% | Oct 6, 2025 | ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources... |
| CVE-2025-11333 | LOW | 2.4 | 0.2% | Oct 6, 2025 | A vulnerability was identified in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. This ... |
| CVE-2025-11322 | LOW | 3.7 | 0.3% | Oct 6, 2025 | A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.... |
| CVE-2025-11308 | LOW | 3.5 | 0.2% | Oct 5, 2025 | A vulnerability was identified in Vanderlande Baggage 360 7.0.0. This issue affects some unknown processing of the file ... |
| CVE-2025-11283 | LOW | 2.4 | 0.4% | Oct 5, 2025 | A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. E... |
| CVE-2025-11280 | LOW | 3.7 | 0.4% | Oct 5, 2025 | A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignm... |
| CVE-2025-61677 | LOW | 2.5 | 0.1% | Oct 3, 2025 | DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and belo... |
| CVE-2025-10306 | LOW | 3.8 | 0.3% | Oct 3, 2025 | The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all version... |
| CVE-2025-54089 | LOW | 3.4 | 0.2% | Oct 2, 2025 | CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with admin... |
| CVE-2025-54087 | LOW | 2.6 | 0.2% | Oct 2, 2025 | CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with ad... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now