2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6541 | HIGH | 8.8 | 0.6% | Oct 21, 2025 | An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. |
| CVE-2025-62658 | HIGH | 7.5 | 0.2% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foun... |
| CVE-2025-61301 | HIGH | 7.5 | 0.4% | Oct 20, 2025 | Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows at... |
| CVE-2025-8052 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | SQL Injection vulnerability in opentext Flipper allows SQL Injection. The vulnerability could allow a low privilege us... |
| CVE-2025-8049 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-62697 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The ... |
| CVE-2025-62527 | HIGH | 7.1 | 0.2% | Oct 20, 2025 | Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ... |
| CVE-2025-61488 | HIGH | 7.6 | 0.3% | Oct 20, 2025 | An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary cod... |
| CVE-2025-62510 | HIGH | 8.1 | 0.3% | Oct 20, 2025 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0... |
| CVE-2025-62509 | HIGH | 8.1 | 0.3% | Oct 20, 2025 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version... |
| CVE-2025-47902 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Pro... |
| CVE-2025-47901 | HIGH | 8.8 | 1.6% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti... |
| CVE-2025-47900 | HIGH | 8.8 | 1.6% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti... |
| CVE-2025-3465 | HIGH | 8.2 | 0.2% | Oct 20, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB C... |
| CVE-2025-62429 | HIGH | 7.2 | 0.8% | Oct 20, 2025 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbi... |
| CVE-2025-40012 | HIGH | 7.8 | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix warning in smc_rx_splice() when callin... |
| CVE-2025-40006 | HIGH | 7.8 | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix folio is still mapped when deleted ... |
| CVE-2025-26782 | HIGH | 7.5 | 0.5% | Oct 20, 2025 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210... |
| CVE-2025-26781 | HIGH | 7.5 | 0.5% | Oct 20, 2025 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210... |
| CVE-2025-61417 | HIGH | 8.8 | 0.5% | Oct 20, 2025 | Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Att... |
| CVE-2025-57738 | HIGH | 7.2 | 23.1% | Oct 20, 2025 | Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide cus... |
| CVE-2025-41390 | HIGH | 7.8 | 0.3% | Oct 20, 2025 | An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A s... |
| CVE-2025-11678 | HIGH | 7.5 | 0.3% | Oct 20, 2025 | Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS fla... |
| CVE-2025-56224 | HIGH | 8.1 | 0.4% | Oct 20, 2025 | A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to by... |
| CVE-2025-56223 | HIGH | 7.5 | 0.4% | Oct 20, 2025 | A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Den... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now