2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40084 | HIGH | 7.1 | 0.2% | Oct 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before ... |
| CVE-2025-64284 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64216 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64195 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-60075 | HIGH | 7.1 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflecte... |
| CVE-2025-11702 | HIGH | 8.8 | 0.6% | Oct 29, 2025 | GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before... |
| CVE-2025-62776 | HIGH | 8.4 | 0.1% | Oct 29, 2025 | The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurel... |
| CVE-2025-62801 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerabi... |
| CVE-2025-62727 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthent... |
| CVE-2025-59837 | HIGH | 7.2 | 0.3% | Oct 28, 2025 | Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy doma... |
| CVE-2025-40843 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
| CVE-2025-12425 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12423 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.... |
| CVE-2025-60805 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive... |
| CVE-2025-60800 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to acce... |
| CVE-2025-60354 | HIGH | 7.5 | 0.2% | Oct 28, 2025 | Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot. |
| CVE-2025-54605 | HIGH | 7.5 | 0.4% | Oct 28, 2025 | Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2). |
| CVE-2025-54604 | HIGH | 7.5 | 0.4% | Oct 28, 2025 | Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2). |
| CVE-2025-60858 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration... |
| CVE-2025-60349 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E... |
| CVE-2025-56399 | HIGH | 8.8 | 0.5% | Oct 28, 2025 | alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) ... |
| CVE-2025-61107 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p... |
| CVE-2025-61106 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p... |
| CVE-2025-61104 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tl... |
| CVE-2025-61103 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_l... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now