2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62185 | HIGH | 7.8 | 0.1% | Oct 7, 2025 | In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, a... |
| CVE-2025-11409 | HIGH | 8.8 | 0.3% | Oct 7, 2025 | A vulnerability was detected in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unkno... |
| CVE-2025-6242 | HIGH | 7.1 | 0.2% | Oct 7, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimod... |
| CVE-2025-61910 | HIGH | 7.5 | 0.3% | Oct 7, 2025 | The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A BP... |
| CVE-2025-44823 | HIGH | 8.8 | 15.6% | Oct 7, 2025 | Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi... |
| CVE-2025-43727 | HIGH | 7.5 | 0.3% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-61784 | HIGH | 8.1 | 0.3% | Oct 7, 2025 | LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF... |
| CVE-2025-43912 | HIGH | 7.5 | 0.3% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43909 | HIGH | 7.5 | 0.1% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43891 | HIGH | 7.5 | 0.2% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43889 | HIGH | 7.5 | 0.3% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4,... |
| CVE-2025-11192 | HIGH | 8.6 | 0.3% | Oct 7, 2025 | A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on... |
| CVE-2025-43914 | HIGH | 7.8 | 0.1% | Oct 7, 2025 | Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS... |
| CVE-2025-36156 | HIGH | 7.8 | 0.1% | Oct 7, 2025 | IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused ... |
| CVE-2025-61772 | HIGH | 7.5 | 0.8% | Oct 7, 2025 | Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` c... |
| CVE-2025-61771 | HIGH | 7.5 | 0.5% | Oct 7, 2025 | Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` ... |
| CVE-2025-61770 | HIGH | 7.5 | 0.8% | Oct 7, 2025 | Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` b... |
| CVE-2025-11398 | HIGH | 8.8 | 0.4% | Oct 7, 2025 | A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unkno... |
| CVE-2025-59425 | HIGH | 7.5 | 0.5% | Oct 7, 2025 | vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support ... |
| CVE-2025-57564 | HIGH | 8.2 | 0.4% | Oct 7, 2025 | CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via... |
| CVE-2025-54406 | HIGH | 8.8 | 4.2% | Oct 7, 2025 | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A... |
| CVE-2025-54405 | HIGH | 8.8 | 4.2% | Oct 7, 2025 | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A... |
| CVE-2025-54404 | HIGH | 8.8 | 3.7% | Oct 7, 2025 | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec... |
| CVE-2025-54403 | HIGH | 8.8 | 3.7% | Oct 7, 2025 | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec... |
| CVE-2025-54402 | HIGH | 8.8 | 0.7% | Oct 7, 2025 | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now