2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61554 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-0... |
| CVE-2025-60358 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations. |
| CVE-2025-62418 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a... |
| CVE-2025-62416 | MEDIUM | 6.8 | 0.4% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SS... |
| CVE-2025-62415 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a... |
| CVE-2025-62414 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin... |
| CVE-2025-61514 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitra... |
| CVE-2025-60855 | MEDIUM | 5.1 | 0.1% | Oct 16, 2025 | Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows ... |
| CVE-2025-34255 | MEDIUM | 5.3 | 1.0% | Oct 16, 2025 | D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic... |
| CVE-2025-34254 | MEDIUM | 5.3 | 1.0% | Oct 16, 2025 | D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic... |
| CVE-2025-34253 | MEDIUM | 5.4 | 0.5% | Oct 16, 2025 | D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to imp... |
| CVE-2025-11852 | MEDIUM | 5.5 | 0.6% | Oct 16, 2025 | A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/... |
| CVE-2025-62413 | MEDIUM | 6.1 | 0.3% | Oct 16, 2025 | MQTTX is an MQTT 5.0 desktop client and MQTT testing tool. A Cross-Site Scripting (XSS) vulnerability was introduced in ... |
| CVE-2025-62412 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules p... |
| CVE-2025-62411 | MEDIUM | 4.8 | 11.6% | Oct 16, 2025 | LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site S... |
| CVE-2025-62407 | MEDIUM | 6.1 | 0.2% | Oct 16, 2025 | Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through t... |
| CVE-2025-61923 | MEDIUM | 4.1 | 0.8% | Oct 16, 2025 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and... |
| CVE-2025-61909 | MEDIUM | 4.4 | 0.2% | Oct 16, 2025 | Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script ... |
| CVE-2025-61908 | MEDIUM | 6.5 | 0.5% | Oct 16, 2025 | Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invali... |
| CVE-2025-61907 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to th... |
| CVE-2025-61330 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment... |
| CVE-2025-60641 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexce... |
| CVE-2025-60639 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26). |
| CVE-2025-34512 | MEDIUM | 6.1 | 0.4% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in i... |
| CVE-2025-61789 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with acce... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now