2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62171 | HIGH | 7.5 | 0.7% | Oct 17, 2025 | ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick ... |
| CVE-2025-62168 | HIGH | 7.5 | 63.3% | Oct 17, 2025 | Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credential... |
| CVE-2025-62356 | HIGH | 7.5 | 0.6% | Oct 17, 2025 | A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local f... |
| CVE-2025-59043 | HIGH | 7.5 | 0.7% | Oct 17, 2025 | OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects aft... |
| CVE-2025-26625 | HIGH | 8.6 | 0.7% | Oct 17, 2025 | Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git re... |
| CVE-2025-11905 | HIGH | 8.8 | 0.7% | Oct 17, 2025 | A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the... |
| CVE-2025-55085 | HIGH | 7.5 | 0.6% | Oct 17, 2025 | In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsi... |
| CVE-2025-11904 | HIGH | 7.2 | 0.6% | Oct 17, 2025 | A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/mo... |
| CVE-2025-48044 | HIGH | 8.6 | 0.7% | Oct 17, 2025 | Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6... |
| CVE-2025-11903 | HIGH | 7.2 | 0.6% | Oct 17, 2025 | A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cm... |
| CVE-2025-11902 | HIGH | 7.2 | 0.6% | Oct 17, 2025 | A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findFie... |
| CVE-2025-55094 | HIGH | 7.5 | 0.4% | Oct 17, 2025 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou... |
| CVE-2025-55087 | HIGH | 7.5 | 0.4% | Oct 17, 2025 | In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an ou... |
| CVE-2025-11898 | HIGH | 8.7 | 0.8% | Oct 17, 2025 | Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers t... |
| CVE-2025-6892 | HIGH | 8.7 | 0.6% | Oct 17, 2025 | An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw i... |
| CVE-2025-62506 | HIGH | 8.1 | 0.5% | Oct 16, 2025 | MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege es... |
| CVE-2025-62504 | HIGH | 7.5 | 0.4% | Oct 16, 2025 | Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain... |
| CVE-2025-11864 | HIGH | 7.3 | 0.4% | Oct 16, 2025 | A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply... |
| CVE-2025-62428 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host ... |
| CVE-2025-62427 | HIGH | 8.7 | 0.4% | Oct 16, 2025 | The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request For... |
| CVE-2025-62425 | HIGH | 8.3 | 0.4% | Oct 16, 2025 | MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and ... |
| CVE-2025-62423 | HIGH | 7.2 | 0.5% | Oct 16, 2025 | ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vul... |
| CVE-2025-62417 | HIGH | 7.8 | 0.4% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character... |
| CVE-2025-61553 | HIGH | 8.2 | 0.2% | Oct 16, 2025 | An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (... |
| CVE-2025-11853 | HIGH | 8.1 | 0.4% | Oct 16, 2025 | A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now