2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62790 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch... |
| CVE-2025-62789 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert... |
| CVE-2025-62788 | HIGH | 7.5 | 0.3% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_ev... |
| CVE-2025-62787 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer ... |
| CVE-2025-61234 | HIGH | 7.5 | 0.3% | Oct 29, 2025 | Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local networ... |
| CVE-2025-60595 | HIGH | 8.2 | 0.3% | Oct 29, 2025 | SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution. |
| CVE-2025-12479 | HIGH | 8.8 | 0.2% | Oct 29, 2025 | Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-... |
| CVE-2025-62786 | HIGH | 8.1 | 0.7% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds... |
| CVE-2025-62785 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation ... |
| CVE-2025-61429 | HIGH | 8.8 | 0.3% | Oct 29, 2025 | An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request... |
| CVE-2025-61156 | HIGH | 7.8 | 0.1% | Oct 29, 2025 | Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privil... |
| CVE-2025-10932 | HIGH | 8.2 | 0.5% | Oct 29, 2025 | Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Trans... |
| CVE-2025-64140 | HIGH | 8.8 | 0.6% | Oct 29, 2025 | Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowin... |
| CVE-2025-64134 | HIGH | 7.1 | 0.3% | Oct 29, 2025 | Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure it... |
| CVE-2025-64131 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtai... |
| CVE-2025-61161 | HIGH | 8.4 | 0.2% | Oct 29, 2025 | DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an un... |
| CVE-2025-40084 | HIGH | 7.1 | 0.2% | Oct 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before ... |
| CVE-2025-64284 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64216 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64195 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-60075 | HIGH | 7.1 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflecte... |
| CVE-2025-11702 | HIGH | 8.8 | 0.6% | Oct 29, 2025 | GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before... |
| CVE-2025-62776 | HIGH | 8.4 | 0.1% | Oct 29, 2025 | The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurel... |
| CVE-2025-62801 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerabi... |
| CVE-2025-62727 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthent... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now