2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6979 | HIGH | 8.8 | 0.5% | Oct 23, 2025 | Captive Portal can allow authentication bypass |
| CVE-2025-6978 | HIGH | 7.2 | 11.7% | Oct 23, 2025 | Diagnostics command injection vulnerability |
| CVE-2025-54808 | HIGH | 7.8 | 0.2% | Oct 23, 2025 | Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file locat... |
| CVE-2025-23352 | HIGH | 7.8 | 0.2% | Oct 23, 2025 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitiali... |
| CVE-2025-23347 | HIGH | 7.8 | 0.1% | Oct 23, 2025 | NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful e... |
| CVE-2025-11621 | HIGH | 8.1 | 0.5% | Oct 23, 2025 | Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the co... |
| CVE-2025-62713 | HIGH | 7.2 | 0.7% | Oct 23, 2025 | Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authenticati... |
| CVE-2025-62169 | HIGH | 8.1 | 0.4% | Oct 23, 2025 | OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of th... |
| CVE-2025-59048 | HIGH | 8.1 | 0.2% | Oct 23, 2025 | OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is v... |
| CVE-2025-50950 | HIGH | 7.5 | 0.3% | Oct 23, 2025 | Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function. |
| CVE-2025-61136 | HIGH | 7.1 | 0.4% | Oct 23, 2025 | A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attack... |
| CVE-2025-61132 | HIGH | 7.1 | 0.3% | Oct 23, 2025 | A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attacker... |
| CVE-2025-62399 | HIGH | 7.5 | 0.4% | Oct 23, 2025 | Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, makin... |
| CVE-2025-12105 | HIGH | 7.5 | 0.4% | Oct 23, 2025 | A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-base... |
| CVE-2025-10914 | HIGH | 7.6 | 0.2% | Oct 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft... |
| CVE-2025-61865 | HIGH | 8.4 | 0.2% | Oct 23, 2025 | Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path... |
| CVE-2025-11575 | HIGH | 8.8 | 0.1% | Oct 23, 2025 | Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This... |
| CVE-2025-62708 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability... |
| CVE-2025-62707 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability... |
| CVE-2025-62617 | HIGH | 7.2 | 0.4% | Oct 22, 2025 | Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerabilit... |
| CVE-2025-62614 | HIGH | 8.7 | 0.5% | Oct 22, 2025 | BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an... |
| CVE-2025-62611 | HIGH | 8.2 | 0.4% | Oct 22, 2025 | aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings ... |
| CVE-2025-62610 | HIGH | 8.1 | 0.4% | Oct 22, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4... |
| CVE-2025-62513 | HIGH | 7.5 | 0.3% | Oct 22, 2025 | OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log expe... |
| CVE-2025-60343 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now