2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54374 | HIGH | 8.8 | 0.5% | Oct 3, 2025 | Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code... |
| CVE-2025-57714 | HIGH | 7.8 | 0.2% | Oct 3, 2025 | An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gain... |
| CVE-2025-54153 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-53595 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-52656 | HIGH | 7.6 | 0.2% | Oct 3, 2025 | HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatica... |
| CVE-2025-47212 | HIGH | 7.2 | 1.4% | Oct 3, 2025 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack... |
| CVE-2025-46819 | HIGH | 7.1 | 1.0% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-46818 | HIGH | 7.3 | 0.7% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-44014 | HIGH | 8.8 | 0.5% | Oct 3, 2025 | An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun... |
| CVE-2025-61593 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI ... |
| CVE-2025-61592 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific ... |
| CVE-2025-46817 | HIGH | 8.8 | 3.7% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-61591 | HIGH | 8.8 | 1.1% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication wit... |
| CVE-2025-61590 | HIGH | 7.5 | 0.5% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (R... |
| CVE-2025-56551 | HIGH | 8.2 | 0.3% | Oct 3, 2025 | An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate lo... |
| CVE-2025-60787 | HIGH | 7.2 | 24.4% | Oct 3, 2025 | MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name... |
| CVE-2025-55972 | HIGH | 7.5 | 0.5% | Oct 3, 2025 | A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Deni... |
| CVE-2025-34226 | HIGH | 7.1 | 0.6% | Oct 3, 2025 | OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field suppli... |
| CVE-2025-59489 | HIGH | 7.4 | 0.6% | Oct 3, 2025 | Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loadi... |
| CVE-2025-9561 | HIGH | 8.8 | 0.6% | Oct 3, 2025 | The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic... |
| CVE-2025-9213 | HIGH | 8.8 | 0.2% | Oct 3, 2025 | The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due... |
| CVE-2025-9212 | HIGH | 7.5 | 0.5% | Oct 3, 2025 | The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-9200 | HIGH | 7.5 | 0.3% | Oct 3, 2025 | The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQ... |
| CVE-2025-27237 | HIGH | 7.3 | 0.3% | Oct 3, 2025 | In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged ... |
| CVE-2025-10582 | HIGH | 8.8 | 0.3% | Oct 3, 2025 | The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now