2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60375 | HIGH | 7.3 | 0.3% | Oct 9, 2025 | The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient... |
| CVE-2025-59271 | HIGH | 8.7 | 0.6% | Oct 9, 2025 | Redis Enterprise Elevation of Privilege Vulnerability |
| CVE-2025-35055 | HIGH | 8.8 | 0.5% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrar... |
| CVE-2025-34248 | HIGH | 7.2 | 0.6% | Oct 9, 2025 | D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/globa... |
| CVE-2025-11554 | HIGH | 8.8 | 0.4% | Oct 9, 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown f... |
| CVE-2025-59146 | HIGH | 8.5 | 0.2% | Oct 9, 2025 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticate... |
| CVE-2025-4615 | HIGH | 7.2 | 0.7% | Oct 9, 2025 | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar... |
| CVE-2025-11552 | HIGH | 8.8 | 0.3% | Oct 9, 2025 | A vulnerability was identified in code-projects Online Complaint Site 1.0. This impacts an unknown function of the file ... |
| CVE-2025-11573 | HIGH | 8.7 | 0.4% | Oct 9, 2025 | An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of servic... |
| CVE-2025-60004 | HIGH | 8.7 | 0.4% | Oct 9, 2025 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne... |
| CVE-2025-11371 | HIGH | 7.5 | 92.1% | Oct 9, 2025 | In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local Fil... |
| CVE-2025-61577 | HIGH | 7.5 | 5.3% | Oct 9, 2025 | D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the d... |
| CVE-2025-59976 | HIGH | 7.1 | 0.3% | Oct 9, 2025 | An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based aut... |
| CVE-2025-59975 | HIGH | 8.7 | 0.4% | Oct 9, 2025 | An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an ... |
| CVE-2025-59968 | HIGH | 8.6 | 0.3% | Oct 9, 2025 | A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated ne... |
| CVE-2025-59967 | HIGH | 7.1 | 0.2% | Oct 9, 2025 | A NULL Pointer Dereference vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved... |
| CVE-2025-59964 | HIGH | 8.7 | 0.3% | Oct 9, 2025 | A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4... |
| CVE-2025-59957 | HIGH | 7 | 0.2% | Oct 9, 2025 | An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series... |
| CVE-2025-52961 | HIGH | 7.1 | 0.4% | Oct 9, 2025 | An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivit... |
| CVE-2025-52960 | HIGH | 8.2 | 0.3% | Oct 9, 2025 | A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol (SIP) ALG of Juniper... |
| CVE-2025-11198 | HIGH | 7.4 | 0.3% | Oct 9, 2025 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allow... |
| CVE-2025-45095 | HIGH | 7.3 | 0.3% | Oct 9, 2025 | Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCISer... |
| CVE-2025-32919 | HIGH | 7.8 | 0.2% | Oct 9, 2025 | Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Esca... |
| CVE-2025-62228 | HIGH | 8.8 | 0.4% | Oct 9, 2025 | Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted databas... |
| CVE-2025-11561 | HIGH | 8.8 | 0.8% | Oct 9, 2025 | A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now