2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11285 | HIGH | 8.8 | 7.9% | Oct 5, 2025 | A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the... |
| CVE-2025-11284 | HIGH | 7.3 | 0.4% | Oct 5, 2025 | A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vul... |
| CVE-2025-11277 | HIGH | 7.8 | 0.2% | Oct 5, 2025 | A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternR... |
| CVE-2025-11275 | HIGH | 7.8 | 0.2% | Oct 5, 2025 | A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function... |
| CVE-2025-39952 | HIGH | 7.8 | 0.2% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: avoid buffer overflow in WID string... |
| CVE-2025-39951 | HIGH | 7.8 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: um: virtio_uml: Fix use-after-free after put_device... |
| CVE-2025-39945 | HIGH | 7.8 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: cnic: Fix use-after-free bugs in cnic_delete_task ... |
| CVE-2025-39944 | HIGH | 7.8 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix use-after-free bugs in otx2_sync_... |
| CVE-2025-39943 | HIGH | 7.1 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: validate data_offset and data_len... |
| CVE-2025-39939 | HIGH | 7.8 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Fix memory corruption when using identi... |
| CVE-2025-39935 | HIGH | 7.8 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: codec: sma1307: Fix memory corruption in sma1... |
| CVE-2025-9243 | HIGH | 8.1 | 0.3% | Oct 4, 2025 | The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capa... |
| CVE-2025-10751 | HIGH | 7.8 | 0.2% | Oct 4, 2025 | MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.Thi... |
| CVE-2025-61679 | HIGH | 7.7 | 0.1% | Oct 3, 2025 | Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained... |
| CVE-2025-61673 | HIGH | 8.6 | 0.4% | Oct 3, 2025 | Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authent... |
| CVE-2025-10692 | HIGH | 7.1 | 0.3% | Oct 3, 2025 | The endpoint POST /api/staff/get-new-tickets concatenates the user-controlled parameter departmentId directly into the S... |
| CVE-2025-54374 | HIGH | 8.8 | 0.5% | Oct 3, 2025 | Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code... |
| CVE-2025-57714 | HIGH | 7.8 | 0.2% | Oct 3, 2025 | An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gain... |
| CVE-2025-54153 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-53595 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-52656 | HIGH | 7.6 | 0.2% | Oct 3, 2025 | HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatica... |
| CVE-2025-47212 | HIGH | 7.2 | 1.4% | Oct 3, 2025 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack... |
| CVE-2025-46819 | HIGH | 7.1 | 1.0% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-46818 | HIGH | 7.3 | 0.7% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-44014 | HIGH | 8.8 | 0.5% | Oct 3, 2025 | An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now