2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59837 | HIGH | 7.2 | 0.3% | Oct 28, 2025 | Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy doma... |
| CVE-2025-40843 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
| CVE-2025-12425 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12423 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.... |
| CVE-2025-60805 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive... |
| CVE-2025-60800 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to acce... |
| CVE-2025-60354 | HIGH | 7.5 | 0.2% | Oct 28, 2025 | Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot. |
| CVE-2025-54605 | HIGH | 7.5 | 0.4% | Oct 28, 2025 | Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2). |
| CVE-2025-54604 | HIGH | 7.5 | 0.4% | Oct 28, 2025 | Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2). |
| CVE-2025-60858 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration... |
| CVE-2025-60349 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E... |
| CVE-2025-56399 | HIGH | 8.8 | 0.5% | Oct 28, 2025 | alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) ... |
| CVE-2025-61107 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p... |
| CVE-2025-61106 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p... |
| CVE-2025-61104 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tl... |
| CVE-2025-61103 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_l... |
| CVE-2025-34312 | HIGH | 8.8 | 2.3% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated a... |
| CVE-2025-34311 | HIGH | 8.8 | 13.8% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated a... |
| CVE-2025-53855 | HIGH | 7.8 | 0.3% | Oct 28, 2025 | An out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A spe... |
| CVE-2025-53814 | HIGH | 7.8 | 0.3% | Oct 28, 2025 | A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially... |
| CVE-2025-1038 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, al... |
| CVE-2025-1037 | HIGH | 7.5 | 0.1% | Oct 28, 2025 | By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user l... |
| CVE-2025-1036 | HIGH | 8.7 | 1.1% | Oct 28, 2025 | Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated us... |
| CVE-2025-40082 | HIGH | 7.1 | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni... |
| CVE-2025-40081 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: perf: arm_spe: Prevent overflow in PERF_IDX2OFF() ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now