2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61666 | HIGH | 8.7 | 1.2% | Oct 2, 2025 | Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and n... |
| CVE-2025-61600 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerabil... |
| CVE-2025-61665 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken ... |
| CVE-2025-61604 | HIGH | 7.1 | 0.2% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-S... |
| CVE-2025-61595 | HIGH | 8.8 | 0.3% | Oct 2, 2025 | MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4... |
| CVE-2025-10653 | HIGH | 8.6 | 0.4% | Oct 2, 2025 | An unauthenticated debug port may allow access to the device file system. |
| CVE-2025-59835 | HIGH | 8.6 | 0.4% | Oct 2, 2025 | LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attac... |
| CVE-2025-54315 | HIGH | 7.1 | 0.3% | Oct 2, 2025 | The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness. |
| CVE-2025-49090 | HIGH | 7.1 | 0.4% | Oct 2, 2025 | The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient... |
| CVE-2025-32942 | HIGH | 7.2 | 0.2% | Oct 2, 2025 | SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic. |
| CVE-2025-60663 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan f... |
| CVE-2025-59409 | HIGH | 7.5 | 0.3% | Oct 2, 2025 | Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck... |
| CVE-2025-59405 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and S... |
| CVE-2025-34208 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords u... |
| CVE-2025-60662 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan... |
| CVE-2025-60660 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan func... |
| CVE-2025-56161 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment... |
| CVE-2025-59745 | HIGH | 7.5 | 0.2% | Oct 2, 2025 | Vulnerability in the cryptographic algorithm of AndSoft's e-TMS v25.03, which uses MD5 to encrypt passwords. MD5 is a cr... |
| CVE-2025-59744 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to access files only withi... |
| CVE-2025-11240 | HIGH | 7.2 | 0.2% | Oct 2, 2025 | An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker... |
| CVE-2025-61735 | HIGH | 7.3 | 0.5% | Oct 2, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5... |
| CVE-2025-61734 | HIGH | 7.5 | 1.3% | Oct 2, 2025 | Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's ... |
| CVE-2025-61733 | HIGH | 7.5 | 1.2% | Oct 2, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin... |
| CVE-2025-54289 | HIGH | 8.1 | 0.2% | Oct 2, 2025 | Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions... |
| CVE-2025-54286 | HIGH | 8.8 | 0.1% | Oct 2, 2025 | Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now