2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52663 | HIGH | 7.3 | 0.2% | Oct 31, 2025 | A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintention... |
| CVE-2025-48984 | HIGH | 8.8 | 1.0% | Oct 31, 2025 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
| CVE-2025-48982 | HIGH | 7.8 | 0.2% | Oct 31, 2025 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator ... |
| CVE-2025-34298 | HIGH | 8.8 | 0.6% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change ... |
| CVE-2025-34287 | HIGH | 7.8 | 0.3% | Oct 30, 2025 | Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodical... |
| CVE-2025-34286 | HIGH | 7.2 | 2.2% | Oct 30, 2025 | Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run C... |
| CVE-2025-34284 | HIGH | 8.8 | 4.1% | Oct 30, 2025 | Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validatio... |
| CVE-2025-34280 | HIGH | 7.2 | 1.3% | Oct 30, 2025 | Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management function... |
| CVE-2025-34134 | HIGH | 7.2 | 2.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligenc... |
| CVE-2025-8850 | HIGH | 8.8 | 0.4% | Oct 30, 2025 | In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow.... |
| CVE-2025-63423 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator passw... |
| CVE-2025-61498 | HIGH | 7.5 | 0.4% | Oct 30, 2025 | A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (... |
| CVE-2025-61141 | HIGH | 7.5 | 1.1% | Oct 30, 2025 | sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes ... |
| CVE-2025-3355 | HIGH | 7.5 | 0.5% | Oct 30, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t... |
| CVE-2025-63422 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRou... |
| CVE-2025-63298 | HIGH | 8.2 | 0.5% | Oct 30, 2025 | A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/... |
| CVE-2025-36137 | HIGH | 7.2 | 0.3% | Oct 30, 2025 | IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 throu... |
| CVE-2025-64112 | HIGH | 8 | 0.3% | Oct 30, 2025 | Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Ta... |
| CVE-2025-64096 | HIGH | 8.8 | 0.5% | Oct 30, 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2025-62795 | HIGH | 7.1 | 0.3% | Oct 30, 2025 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts ... |
| CVE-2025-62726 | HIGH | 8.8 | 0.8% | Oct 30, 2025 | n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in th... |
| CVE-2025-61196 | HIGH | 8.8 | 0.5% | Oct 30, 2025 | An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input pa... |
| CVE-2025-61121 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., ... |
| CVE-2025-61120 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., con... |
| CVE-2025-61119 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access cont... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now