2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11903 | HIGH | 7.2 | 0.6% | Oct 17, 2025 | A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cm... |
| CVE-2025-11902 | HIGH | 7.2 | 0.6% | Oct 17, 2025 | A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findFie... |
| CVE-2025-55094 | HIGH | 7.5 | 0.4% | Oct 17, 2025 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou... |
| CVE-2025-55087 | HIGH | 7.5 | 0.4% | Oct 17, 2025 | In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an ou... |
| CVE-2025-11898 | HIGH | 8.7 | 0.8% | Oct 17, 2025 | Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers t... |
| CVE-2025-6892 | HIGH | 8.7 | 0.6% | Oct 17, 2025 | An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw i... |
| CVE-2025-62506 | HIGH | 8.1 | 0.5% | Oct 16, 2025 | MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege es... |
| CVE-2025-62504 | HIGH | 7.5 | 0.4% | Oct 16, 2025 | Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain... |
| CVE-2025-11864 | HIGH | 7.3 | 0.4% | Oct 16, 2025 | A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply... |
| CVE-2025-62428 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host ... |
| CVE-2025-62427 | HIGH | 8.7 | 0.4% | Oct 16, 2025 | The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request For... |
| CVE-2025-62425 | HIGH | 8.3 | 0.4% | Oct 16, 2025 | MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and ... |
| CVE-2025-62423 | HIGH | 7.2 | 0.5% | Oct 16, 2025 | ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vul... |
| CVE-2025-62417 | HIGH | 7.8 | 0.4% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character... |
| CVE-2025-61553 | HIGH | 8.2 | 0.2% | Oct 16, 2025 | An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (... |
| CVE-2025-11853 | HIGH | 8.1 | 0.4% | Oct 16, 2025 | A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of th... |
| CVE-2025-11493 | HIGH | 7.5 | 0.2% | Oct 16, 2025 | The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updat... |
| CVE-2025-11492 | HIGH | 7.5 | 0.2% | Oct 16, 2025 | In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on... |
| CVE-2025-62409 | HIGH | 7.5 | 0.4% | Oct 16, 2025 | Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large request... |
| CVE-2025-34519 | HIGH | 7.5 | 0.3% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product ... |
| CVE-2025-34518 | HIGH | 7.5 | 0.6% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_conte... |
| CVE-2025-34517 | HIGH | 7.5 | 0.6% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_cont... |
| CVE-2025-34514 | HIGH | 8.8 | 2.1% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in mul... |
| CVE-2025-36128 | HIGH | 7.5 | 0.5% | Oct 16, 2025 | IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of th... |
| CVE-2025-62496 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to cr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now