2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10151 | HIGH | 7.2 | 0.2% | Oct 28, 2025 | Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource lea... |
| CVE-2025-10150 | HIGH | 8.7 | 0.2% | Oct 28, 2025 | Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue a... |
| CVE-2025-11735 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via t... |
| CVE-2025-62777 | HIGH | 8.8 | 0.2% | Oct 28, 2025 | Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within th... |
| CVE-2025-12347 | HIGH | 8.8 | 0.4% | Oct 28, 2025 | A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsi... |
| CVE-2025-12346 | HIGH | 8.8 | 0.4% | Oct 28, 2025 | A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/m... |
| CVE-2025-12342 | HIGH | 7.3 | 0.3% | Oct 28, 2025 | A flaw has been found in Serdar Bayram Ghost Hot Spot up to 20251014. The affected element is an unknown function of the... |
| CVE-2025-12341 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | A vulnerability was detected in ermig1979 AntiDupl up to 2.3.12. Impacted is an unknown function of the file AntiDupl.NE... |
| CVE-2025-43024 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | A GUI dialog of an application allows to view what files are in the file system without proper authorization. |
| CVE-2025-62260 | HIGH | 7.5 | 0.4% | Oct 27, 2025 | Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA thr... |
| CVE-2025-12331 | HIGH | 7.2 | 0.4% | Oct 27, 2025 | A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add.... |
| CVE-2025-62725 | HIGH | 8.9 | 13.8% | Oct 27, 2025 | Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotatio... |
| CVE-2025-12326 | HIGH | 7.5 | 0.4% | Oct 27, 2025 | A vulnerability was found in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. This vulnerability affect... |
| CVE-2025-12322 | HIGH | 8.8 | 0.7% | Oct 27, 2025 | A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromNatStaticSetting of the file /go... |
| CVE-2025-61105 | HIGH | 7.5 | 0.5% | Oct 27, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info ... |
| CVE-2025-61102 | HIGH | 7.5 | 0.5% | Oct 27, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_a... |
| CVE-2025-61101 | HIGH | 7.5 | 0.5% | Oct 27, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_r... |
| CVE-2025-59151 | HIGH | 8.2 | 0.4% | Oct 27, 2025 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker bloc... |
| CVE-2025-58356 | HIGH | 8.3 | 0.1% | Oct 27, 2025 | Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persist... |
| CVE-2025-61100 | HIGH | 7.5 | 0.5% | Oct 27, 2025 | FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dum... |
| CVE-2025-61099 | HIGH | 7.5 | 0.5% | Oct 27, 2025 | FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail ... |
| CVE-2025-36007 | HIGH | 7.8 | 0.1% | Oct 27, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to imprope... |
| CVE-2025-55752 | HIGH | 7.5 | 66.5% | Oct 27, 2025 | Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the r... |
| CVE-2025-12363 | HIGH | 7.5 | 0.3% | Oct 27, 2025 | Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-54968 | HIGH | 8.8 | 0.4% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now