2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62495 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent rep... |
| CVE-2025-62494 | HIGH | 8.8 | 0.5% | Oct 16, 2025 | A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. ... |
| CVE-2025-62491 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list... |
| CVE-2025-62490 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over ... |
| CVE-2025-61543 | HIGH | 7.1 | 0.3% | Oct 16, 2025 | A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses ... |
| CVE-2025-61541 | HIGH | 7.1 | 0.4% | Oct 16, 2025 | Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset l... |
| CVE-2025-61536 | HIGH | 8.2 | 0.4% | Oct 16, 2025 | FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` he... |
| CVE-2025-41253 | HIGH | 7.5 | 0.4% | Oct 16, 2025 | The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment var... |
| CVE-2025-22381 | HIGH | 8.2 | 0.6% | Oct 16, 2025 | Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to rese... |
| CVE-2025-54658 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2025-53951 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2025-61581 | HIGH | 7.5 | 0.7% | Oct 16, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This... |
| CVE-2025-58075 | HIGH | 8.1 | 0.3% | Oct 16, 2025 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo... |
| CVE-2025-58073 | HIGH | 8.1 | 0.4% | Oct 16, 2025 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo... |
| CVE-2025-41020 | HIGH | 7.5 | 0.3% | Oct 16, 2025 | Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker t... |
| CVE-2025-62585 | HIGH | 7.5 | 0.3% | Oct 16, 2025 | Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dua... |
| CVE-2025-62584 | HIGH | 7.5 | 0.2% | Oct 16, 2025 | Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment. |
| CVE-2025-10706 | HIGH | 8.8 | 0.6% | Oct 16, 2025 | The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability che... |
| CVE-2025-58778 | HIGH | 8.6 | 0.5% | Oct 16, 2025 | Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the... |
| CVE-2025-62580 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | ASDA-Soft Stack-based Buffer Overflow Vulnerability |
| CVE-2025-62579 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | ASDA-Soft Stack-based Buffer Overflow Vulnerability |
| CVE-2025-43281 | HIGH | 7.8 | 0.1% | Oct 15, 2025 | The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be... |
| CVE-2025-11619 | HIGH | 8.8 | 0.2% | Oct 15, 2025 | Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers ... |
| CVE-2025-62382 | HIGH | 7.7 | 0.3% | Oct 15, 2025 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.2, Frigate'... |
| CVE-2025-62381 | HIGH | 8.3 | 0.5% | Oct 15, 2025 | sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now