2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50950 | HIGH | 7.5 | 0.3% | Oct 23, 2025 | Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function. |
| CVE-2025-61136 | HIGH | 7.1 | 0.4% | Oct 23, 2025 | A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attack... |
| CVE-2025-61132 | HIGH | 7.1 | 0.3% | Oct 23, 2025 | A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attacker... |
| CVE-2025-62399 | HIGH | 7.5 | 0.4% | Oct 23, 2025 | Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, makin... |
| CVE-2025-12105 | HIGH | 7.5 | 0.4% | Oct 23, 2025 | A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-base... |
| CVE-2025-10914 | HIGH | 7.6 | 0.2% | Oct 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft... |
| CVE-2025-61865 | HIGH | 8.4 | 0.2% | Oct 23, 2025 | Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path... |
| CVE-2025-11575 | HIGH | 8.8 | 0.1% | Oct 23, 2025 | Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This... |
| CVE-2025-62708 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability... |
| CVE-2025-62707 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability... |
| CVE-2025-62617 | HIGH | 7.2 | 0.4% | Oct 22, 2025 | Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerabilit... |
| CVE-2025-62614 | HIGH | 8.7 | 0.5% | Oct 22, 2025 | BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an... |
| CVE-2025-62611 | HIGH | 8.2 | 0.4% | Oct 22, 2025 | aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings ... |
| CVE-2025-62610 | HIGH | 8.1 | 0.4% | Oct 22, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4... |
| CVE-2025-62513 | HIGH | 7.5 | 0.3% | Oct 22, 2025 | OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log expe... |
| CVE-2025-60343 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial ... |
| CVE-2025-60342 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. ... |
| CVE-2025-60341 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set... |
| CVE-2025-60340 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial o... |
| CVE-2025-60339 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to ca... |
| CVE-2025-60337 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan fun... |
| CVE-2025-60336 | HIGH | 7.5 | 1.7% | Oct 22, 2025 | A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to caus... |
| CVE-2025-8677 | HIGH | 7.5 | 11.0% | Oct 22, 2025 | Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaust... |
| CVE-2025-60338 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient functi... |
| CVE-2025-60335 | HIGH | 7.5 | 2.0% | Oct 22, 2025 | A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a De... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now