2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62509 | HIGH | 8.1 | 0.3% | Oct 20, 2025 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version... |
| CVE-2025-47902 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Pro... |
| CVE-2025-47901 | HIGH | 8.8 | 1.6% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti... |
| CVE-2025-47900 | HIGH | 8.8 | 1.6% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti... |
| CVE-2025-3465 | HIGH | 8.2 | 0.2% | Oct 20, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB C... |
| CVE-2025-62429 | HIGH | 7.2 | 0.8% | Oct 20, 2025 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbi... |
| CVE-2025-40012 | HIGH | 7.8 | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix warning in smc_rx_splice() when callin... |
| CVE-2025-40006 | HIGH | 7.8 | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix folio is still mapped when deleted ... |
| CVE-2025-26782 | HIGH | 7.5 | 0.5% | Oct 20, 2025 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210... |
| CVE-2025-26781 | HIGH | 7.5 | 0.5% | Oct 20, 2025 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210... |
| CVE-2025-61417 | HIGH | 8.8 | 0.5% | Oct 20, 2025 | Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Att... |
| CVE-2025-57738 | HIGH | 7.2 | 23.1% | Oct 20, 2025 | Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide cus... |
| CVE-2025-41390 | HIGH | 7.8 | 0.3% | Oct 20, 2025 | An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A s... |
| CVE-2025-11678 | HIGH | 7.5 | 0.3% | Oct 20, 2025 | Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS fla... |
| CVE-2025-56224 | HIGH | 8.1 | 0.4% | Oct 20, 2025 | A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to by... |
| CVE-2025-56223 | HIGH | 7.5 | 0.4% | Oct 20, 2025 | A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Den... |
| CVE-2025-56219 | HIGH | 7.1 | 0.3% | Oct 20, 2025 | Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limitin... |
| CVE-2025-62577 | HIGH | 8.8 | 0.2% | Oct 20, 2025 | ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged ... |
| CVE-2025-11944 | HIGH | 7.2 | 0.5% | Oct 19, 2025 | A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/control... |
| CVE-2025-11941 | HIGH | 8.1 | 0.8% | Oct 19, 2025 | A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php... |
| CVE-2025-11940 | HIGH | 7.3 | 0.2% | Oct 19, 2025 | A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of ... |
| CVE-2025-11939 | HIGH | 7.2 | 0.9% | Oct 19, 2025 | A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/Chu... |
| CVE-2025-11938 | HIGH | 8.1 | 0.7% | Oct 19, 2025 | A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/se... |
| CVE-2025-47410 | HIGH | 8.8 | 0.3% | Oct 18, 2025 | Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could all... |
| CVE-2025-9890 | HIGH | 8.8 | 0.4% | Oct 18, 2025 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now