2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8850 | HIGH | 8.8 | 0.4% | Oct 30, 2025 | In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow.... |
| CVE-2025-63423 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator passw... |
| CVE-2025-61498 | HIGH | 7.5 | 0.4% | Oct 30, 2025 | A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (... |
| CVE-2025-61141 | HIGH | 7.5 | 1.1% | Oct 30, 2025 | sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes ... |
| CVE-2025-3355 | HIGH | 7.5 | 0.5% | Oct 30, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t... |
| CVE-2025-63422 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRou... |
| CVE-2025-63298 | HIGH | 8.2 | 0.5% | Oct 30, 2025 | A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/... |
| CVE-2025-36137 | HIGH | 7.2 | 0.3% | Oct 30, 2025 | IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 throu... |
| CVE-2025-64112 | HIGH | 8 | 0.3% | Oct 30, 2025 | Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Ta... |
| CVE-2025-64096 | HIGH | 8.8 | 0.5% | Oct 30, 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2025-62795 | HIGH | 7.1 | 0.3% | Oct 30, 2025 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts ... |
| CVE-2025-62726 | HIGH | 8.8 | 0.8% | Oct 30, 2025 | n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in th... |
| CVE-2025-61196 | HIGH | 8.8 | 0.5% | Oct 30, 2025 | An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input pa... |
| CVE-2025-61121 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., ... |
| CVE-2025-61120 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., con... |
| CVE-2025-61119 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access cont... |
| CVE-2025-61114 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | 2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., con... |
| CVE-2025-12060 | HIGH | 8.9 | 0.6% | Oct 30, 2025 | The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path ... |
| CVE-2025-62712 | HIGH | 8.1 | 0.5% | Oct 30, 2025 | JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions... |
| CVE-2025-61118 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper acces... |
| CVE-2025-61117 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an impro... |
| CVE-2025-61116 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arsh... |
| CVE-2025-61115 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed... |
| CVE-2025-61113 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API endpoints. By modifying requ... |
| CVE-2025-46423 | HIGH | 7.8 | 0.5% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now