2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10921 | HIGH | 7.8 | 0.5% | Oct 29, 2025 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2025-10920 | HIGH | 7.8 | 0.4% | Oct 29, 2025 | GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attacke... |
| CVE-2025-64104 | HIGH | 7.3 | 0.2% | Oct 29, 2025 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2025-64101 | HIGH | 8.8 | 0.3% | Oct 29, 2025 | Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability e... |
| CVE-2025-62797 | HIGH | 8.6 | 0.2% | Oct 29, 2025 | FluxCP is a web-based Control Panel for rAthena servers written in PHP. A critical Cross-Site Request Forgery (CSRF) vul... |
| CVE-2025-57227 | HIGH | 7.8 | 0.1% | Oct 29, 2025 | An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via ... |
| CVE-2025-11232 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at th... |
| CVE-2025-62792 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer ... |
| CVE-2025-62791 | HIGH | 7.5 | 0.3% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, DecodeCis... |
| CVE-2025-62790 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch... |
| CVE-2025-62789 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert... |
| CVE-2025-62788 | HIGH | 7.5 | 0.3% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_ev... |
| CVE-2025-62787 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer ... |
| CVE-2025-61234 | HIGH | 7.5 | 0.3% | Oct 29, 2025 | Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local networ... |
| CVE-2025-60595 | HIGH | 8.2 | 0.3% | Oct 29, 2025 | SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution. |
| CVE-2025-12479 | HIGH | 8.8 | 0.2% | Oct 29, 2025 | Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-... |
| CVE-2025-62786 | HIGH | 8.1 | 0.7% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds... |
| CVE-2025-62785 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation ... |
| CVE-2025-61429 | HIGH | 8.8 | 0.3% | Oct 29, 2025 | An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request... |
| CVE-2025-61156 | HIGH | 7.8 | 0.1% | Oct 29, 2025 | Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privil... |
| CVE-2025-10932 | HIGH | 8.2 | 0.5% | Oct 29, 2025 | Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Trans... |
| CVE-2025-64140 | HIGH | 8.8 | 0.6% | Oct 29, 2025 | Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowin... |
| CVE-2025-64134 | HIGH | 7.1 | 0.3% | Oct 29, 2025 | Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure it... |
| CVE-2025-64131 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtai... |
| CVE-2025-61161 | HIGH | 8.4 | 0.2% | Oct 29, 2025 | DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an un... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now