2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62518 | HIGH | 8.1 | 0.7% | Oct 21, 2025 | astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 co... |
| CVE-2025-60500 | HIGH | 7.2 | 0.5% | Oct 21, 2025 | QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass... |
| CVE-2025-61220 | HIGH | 7.5 | 0.3% | Oct 21, 2025 | The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other... |
| CVE-2025-60751 | HIGH | 7.5 | 2.2% | Oct 21, 2025 | GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode. |
| CVE-2025-22166 | HIGH | 7.5 | 0.5% | Oct 21, 2025 | This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. Thi... |
| CVE-2025-60344 | HIGH | 8.6 | 10.3% | Oct 21, 2025 | A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker... |
| CVE-2025-9339 | HIGH | 7.1 | 0.3% | Oct 21, 2025 | SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in u... |
| CVE-2025-11151 | HIGH | 8.2 | 0.3% | Oct 21, 2025 | Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized ... |
| CVE-2025-10020 | HIGH | 8.8 | 4.7% | Oct 21, 2025 | Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability... |
| CVE-2025-9428 | HIGH | 8.8 | 25.4% | Oct 21, 2025 | Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key u... |
| CVE-2025-10641 | HIGH | 7.1 | 0.3% | Oct 21, 2025 | All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This a... |
| CVE-2025-10639 | HIGH | 8.8 | 0.9% | Oct 21, 2025 | The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TC... |
| CVE-2025-11949 | HIGH | 8.7 | 0.4% | Oct 21, 2025 | EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthentic... |
| CVE-2025-9133 | HIGH | 8.1 | 5.5% | Oct 21, 2025 | A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series fi... |
| CVE-2025-8078 | HIGH | 7.2 | 1.5% | Oct 21, 2025 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, US... |
| CVE-2025-7850 | HIGH | 7.2 | 2.2% | Oct 21, 2025 | A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. |
| CVE-2025-6541 | HIGH | 8.8 | 0.6% | Oct 21, 2025 | An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. |
| CVE-2025-62658 | HIGH | 7.5 | 0.2% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foun... |
| CVE-2025-61301 | HIGH | 7.5 | 0.4% | Oct 20, 2025 | Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows at... |
| CVE-2025-8052 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | SQL Injection vulnerability in opentext Flipper allows SQL Injection. The vulnerability could allow a low privilege us... |
| CVE-2025-8049 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-62697 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The ... |
| CVE-2025-62527 | HIGH | 7.1 | 0.2% | Oct 20, 2025 | Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ... |
| CVE-2025-61488 | HIGH | 7.6 | 0.3% | Oct 20, 2025 | An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary cod... |
| CVE-2025-62510 | HIGH | 8.1 | 0.3% | Oct 20, 2025 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now