2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63464 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396... |
| CVE-2025-63463 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_42... |
| CVE-2025-63462 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4... |
| CVE-2025-63461 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldec... |
| CVE-2025-63460 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42... |
| CVE-2025-63469 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BA... |
| CVE-2025-63468 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_... |
| CVE-2025-63467 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42540... |
| CVE-2025-63466 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_4... |
| CVE-2025-12509 | HIGH | 8.4 | 0.3% | Oct 31, 2025 | On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the B... |
| CVE-2025-12508 | HIGH | 8.4 | 0.2% | Oct 31, 2025 | When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to t... |
| CVE-2025-12507 | HIGH | 8.8 | 0.1% | Oct 31, 2025 | The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executa... |
| CVE-2025-64389 | HIGH | 8.3 | 0.2% | Oct 31, 2025 | The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol. |
| CVE-2025-64168 | HIGH | 7.1 | 0.1% | Oct 31, 2025 | Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when ses... |
| CVE-2025-60749 | HIGH | 7.8 | 0.2% | Oct 31, 2025 | DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe. |
| CVE-2025-57107 | HIGH | 7.1 | 0.2% | Oct 31, 2025 | Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader... |
| CVE-2025-57106 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerabi... |
| CVE-2025-12501 | HIGH | 7.5 | 0.5% | Oct 31, 2025 | Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-... |
| CVE-2025-64386 | HIGH | 7.7 | 0.3% | Oct 31, 2025 | The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of... |
| CVE-2025-33003 | HIGH | 7.8 | 0.1% | Oct 31, 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabi... |
| CVE-2025-64366 | HIGH | 7.6 | 0.3% | Oct 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu... |
| CVE-2025-64364 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64363 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64360 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64359 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now