2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11234 | HIGH | 7.5 | 0.9% | Oct 3, 2025 | A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSourc... |
| CVE-2025-11223 | HIGH | 8.4 | 0.1% | Oct 3, 2025 | Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead ... |
| CVE-2025-0616 | HIGH | 8.2 | 0.3% | Oct 3, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center ... |
| CVE-2025-59536 | HIGH | 8.8 | 29.3% | Oct 3, 2025 | Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the sta... |
| CVE-2025-59300 | HIGH | 7.8 | 0.2% | Oct 3, 2025 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta... |
| CVE-2025-59299 | HIGH | 7.8 | 0.1% | Oct 3, 2025 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta... |
| CVE-2025-59298 | HIGH | 7.8 | 0.2% | Oct 3, 2025 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta... |
| CVE-2025-59297 | HIGH | 7.8 | 0.2% | Oct 3, 2025 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta... |
| CVE-2025-61668 | HIGH | 8.7 | 0.4% | Oct 2, 2025 | Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17... |
| CVE-2025-61666 | HIGH | 8.7 | 1.2% | Oct 2, 2025 | Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and n... |
| CVE-2025-61600 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerabil... |
| CVE-2025-61665 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken ... |
| CVE-2025-61604 | HIGH | 7.1 | 0.2% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-S... |
| CVE-2025-61595 | HIGH | 8.8 | 0.3% | Oct 2, 2025 | MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4... |
| CVE-2025-10653 | HIGH | 8.6 | 0.4% | Oct 2, 2025 | An unauthenticated debug port may allow access to the device file system. |
| CVE-2025-59835 | HIGH | 8.6 | 0.4% | Oct 2, 2025 | LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attac... |
| CVE-2025-54315 | HIGH | 7.1 | 0.3% | Oct 2, 2025 | The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness. |
| CVE-2025-49090 | HIGH | 7.1 | 0.4% | Oct 2, 2025 | The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient... |
| CVE-2025-32942 | HIGH | 7.2 | 0.2% | Oct 2, 2025 | SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic. |
| CVE-2025-60663 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan f... |
| CVE-2025-59409 | HIGH | 7.5 | 0.3% | Oct 2, 2025 | Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck... |
| CVE-2025-59405 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and S... |
| CVE-2025-34208 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords u... |
| CVE-2025-60662 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan... |
| CVE-2025-60660 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan func... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now