2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11493 | HIGH | 7.5 | 0.2% | Oct 16, 2025 | The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updat... |
| CVE-2025-11492 | HIGH | 7.5 | 0.2% | Oct 16, 2025 | In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on... |
| CVE-2025-62409 | HIGH | 7.5 | 0.4% | Oct 16, 2025 | Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large request... |
| CVE-2025-34519 | HIGH | 7.5 | 0.3% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product ... |
| CVE-2025-34518 | HIGH | 7.5 | 0.6% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_conte... |
| CVE-2025-34517 | HIGH | 7.5 | 0.6% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_cont... |
| CVE-2025-34514 | HIGH | 8.8 | 2.1% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in mul... |
| CVE-2025-36128 | HIGH | 7.5 | 0.5% | Oct 16, 2025 | IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of th... |
| CVE-2025-62496 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to cr... |
| CVE-2025-62495 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent rep... |
| CVE-2025-62494 | HIGH | 8.8 | 0.5% | Oct 16, 2025 | A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. ... |
| CVE-2025-62491 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list... |
| CVE-2025-62490 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over ... |
| CVE-2025-61543 | HIGH | 7.1 | 0.3% | Oct 16, 2025 | A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses ... |
| CVE-2025-61541 | HIGH | 7.1 | 0.4% | Oct 16, 2025 | Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset l... |
| CVE-2025-61536 | HIGH | 8.2 | 0.4% | Oct 16, 2025 | FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` he... |
| CVE-2025-41253 | HIGH | 7.5 | 0.4% | Oct 16, 2025 | The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment var... |
| CVE-2025-22381 | HIGH | 8.2 | 0.6% | Oct 16, 2025 | Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to rese... |
| CVE-2025-54658 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2025-53951 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2025-61581 | HIGH | 7.5 | 0.7% | Oct 16, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This... |
| CVE-2025-58075 | HIGH | 8.1 | 0.3% | Oct 16, 2025 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo... |
| CVE-2025-58073 | HIGH | 8.1 | 0.4% | Oct 16, 2025 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo... |
| CVE-2025-41020 | HIGH | 7.5 | 0.3% | Oct 16, 2025 | Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker t... |
| CVE-2025-62585 | HIGH | 7.5 | 0.3% | Oct 16, 2025 | Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dua... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now