2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5009 | LOW | 1 | 0.1% | Oct 8, 2025 | In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire conversation via a sharable pub... |
| CVE-2025-11441 | LOW | 3.7 | 0.6% | Oct 8, 2025 | A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the compon... |
| CVE-2025-61786 | LOW | 3.3 | 0.2% | Oct 8, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype... |
| CVE-2025-61785 | LOW | 3.3 | 0.2% | Oct 8, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype... |
| CVE-2025-62187 | LOW | 3.3 | 0.2% | Oct 7, 2025 | In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations o... |
| CVE-2025-61670 | LOW | 3.3 | 0.2% | Oct 7, 2025 | Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings... |
| CVE-2025-59451 | LOW | 3.5 | 0.3% | Oct 6, 2025 | The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes. |
| CVE-2025-59447 | LOW | 2.2 | 0.2% | Oct 6, 2025 | The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can lev... |
| CVE-2025-61985 | LOW | 3.6 | 0.1% | Oct 6, 2025 | ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a Prox... |
| CVE-2025-61984 | LOW | 3.6 | 0.2% | Oct 6, 2025 | ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources... |
| CVE-2025-11333 | LOW | 2.4 | 0.2% | Oct 6, 2025 | A vulnerability was identified in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. This ... |
| CVE-2025-11322 | LOW | 3.7 | 0.3% | Oct 6, 2025 | A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.... |
| CVE-2025-11308 | LOW | 3.5 | 0.2% | Oct 5, 2025 | A vulnerability was identified in Vanderlande Baggage 360 7.0.0. This issue affects some unknown processing of the file ... |
| CVE-2025-11283 | LOW | 2.4 | 0.4% | Oct 5, 2025 | A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. E... |
| CVE-2025-11280 | LOW | 3.7 | 0.4% | Oct 5, 2025 | A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignm... |
| CVE-2025-61677 | LOW | 2.5 | 0.1% | Oct 3, 2025 | DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and belo... |
| CVE-2025-10306 | LOW | 3.8 | 0.3% | Oct 3, 2025 | The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all version... |
| CVE-2025-54089 | LOW | 3.4 | 0.2% | Oct 2, 2025 | CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with admin... |
| CVE-2025-54087 | LOW | 2.6 | 0.2% | Oct 2, 2025 | CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with ad... |
| CVE-2025-54086 | LOW | 3.3 | 0.2% | Oct 2, 2025 | CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to vers... |
| CVE-2025-58769 | LOW | 3.3 | 0.3% | Oct 1, 2025 | auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import... |
| CVE-2025-43718 | LOW | 2.9 | 0.1% | Oct 1, 2025 | Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within t... |
| CVE-2025-56675 | LOW | 3.5 | 0.2% | Sep 30, 2025 | The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers wi... |
| CVE-2025-23291 | LOW | 2.4 | 0.1% | Sep 30, 2025 | NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause... |
| CVE-2025-11195 | LOW | 3.3 | 0.1% | Sep 30, 2025 | Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now