2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48087 | MEDIUM | 6.5 | 0.2% | Oct 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlit... |
| CVE-2025-60360 | MEDIUM | 5.5 | 0.2% | Oct 17, 2025 | radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init. |
| CVE-2025-60359 | MEDIUM | 5.5 | 0.2% | Oct 17, 2025 | radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new. |
| CVE-2025-11895 | MEDIUM | 4.3 | 0.2% | Oct 17, 2025 | The Binary MLM Plan plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and includ... |
| CVE-2025-55099 | MEDIUM | 6.1 | 0.3% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-55098 | MEDIUM | 6.1 | 0.3% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-55097 | MEDIUM | 6.1 | 0.2% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-55096 | MEDIUM | 6.1 | 0.2% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-55093 | MEDIUM | 5.3 | 0.3% | Oct 17, 2025 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou... |
| CVE-2025-55092 | MEDIUM | 5.3 | 0.3% | Oct 17, 2025 | In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a p... |
| CVE-2025-6894 | MEDIUM | 5.3 | 0.5% | Oct 17, 2025 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou... |
| CVE-2025-61554 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-0... |
| CVE-2025-60358 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations. |
| CVE-2025-62418 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a... |
| CVE-2025-62416 | MEDIUM | 6.8 | 0.4% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SS... |
| CVE-2025-62415 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a... |
| CVE-2025-62414 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin... |
| CVE-2025-61514 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitra... |
| CVE-2025-60855 | MEDIUM | 5.1 | 0.1% | Oct 16, 2025 | Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows ... |
| CVE-2025-34255 | MEDIUM | 5.3 | 1.0% | Oct 16, 2025 | D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic... |
| CVE-2025-34254 | MEDIUM | 5.3 | 1.0% | Oct 16, 2025 | D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic... |
| CVE-2025-34253 | MEDIUM | 5.4 | 0.5% | Oct 16, 2025 | D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to imp... |
| CVE-2025-11852 | MEDIUM | 5.5 | 0.6% | Oct 16, 2025 | A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/... |
| CVE-2025-62413 | MEDIUM | 6.1 | 0.3% | Oct 16, 2025 | MQTTX is an MQTT 5.0 desktop client and MQTT testing tool. A Cross-Site Scripting (XSS) vulnerability was introduced in ... |
| CVE-2025-62412 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now