2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5555 | HIGH | 7.8 | 0.2% | Oct 18, 2025 | A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in th... |
| CVE-2025-11691 | HIGH | 7.5 | 0.4% | Oct 18, 2025 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PP... |
| CVE-2025-11517 | HIGH | 7.5 | 0.4% | Oct 18, 2025 | The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and inclu... |
| CVE-2025-62646 | HIGH | 7.7 | 0.5% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the st... |
| CVE-2025-62644 | HIGH | 7.7 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares... |
| CVE-2025-62643 | HIGH | 8.6 | 0.3% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in ... |
| CVE-2025-62642 | HIGH | 8.6 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" sign... |
| CVE-2025-11914 | HIGH | 7.5 | 0.8% | Oct 17, 2025 | A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function ... |
| CVE-2025-11912 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file ... |
| CVE-2025-11911 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of t... |
| CVE-2025-11910 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the funct... |
| CVE-2025-11909 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the functi... |
| CVE-2025-11908 | HIGH | 8.8 | 0.5% | Oct 17, 2025 | A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the f... |
| CVE-2025-62422 | HIGH | 8.8 | 0.5% | Oct 17, 2025 | DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datas... |
| CVE-2025-62420 | HIGH | 8.8 | 0.9% | Oct 17, 2025 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vuln... |
| CVE-2025-62419 | HIGH | 7.5 | 0.4% | Oct 17, 2025 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vuln... |
| CVE-2025-62171 | HIGH | 7.5 | 0.7% | Oct 17, 2025 | ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick ... |
| CVE-2025-62168 | HIGH | 7.5 | 63.3% | Oct 17, 2025 | Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credential... |
| CVE-2025-62356 | HIGH | 7.5 | 0.6% | Oct 17, 2025 | A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local f... |
| CVE-2025-59043 | HIGH | 7.5 | 0.7% | Oct 17, 2025 | OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects aft... |
| CVE-2025-26625 | HIGH | 8.6 | 0.7% | Oct 17, 2025 | Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git re... |
| CVE-2025-11905 | HIGH | 8.8 | 0.7% | Oct 17, 2025 | A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the... |
| CVE-2025-55085 | HIGH | 7.5 | 0.6% | Oct 17, 2025 | In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsi... |
| CVE-2025-11904 | HIGH | 7.2 | 0.6% | Oct 17, 2025 | A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/mo... |
| CVE-2025-48044 | HIGH | 8.6 | 0.8% | Oct 17, 2025 | Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now