2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62411 | MEDIUM | 4.8 | 11.6% | Oct 16, 2025 | LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site S... |
| CVE-2025-62407 | MEDIUM | 6.1 | 0.2% | Oct 16, 2025 | Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through t... |
| CVE-2025-61923 | MEDIUM | 4.1 | 0.8% | Oct 16, 2025 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and... |
| CVE-2025-61909 | MEDIUM | 4.4 | 0.2% | Oct 16, 2025 | Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script ... |
| CVE-2025-61908 | MEDIUM | 6.5 | 0.5% | Oct 16, 2025 | Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invali... |
| CVE-2025-61907 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to th... |
| CVE-2025-61330 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment... |
| CVE-2025-60641 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexce... |
| CVE-2025-60639 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26). |
| CVE-2025-34512 | MEDIUM | 6.1 | 0.4% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in i... |
| CVE-2025-61789 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with acce... |
| CVE-2025-58051 | MEDIUM | 6.5 | 0.5% | Oct 16, 2025 | Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when impor... |
| CVE-2025-56700 | MEDIUM | 5.4 | 0.2% | Oct 16, 2025 | Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allo... |
| CVE-2025-56699 | MEDIUM | 5.4 | 0.3% | Oct 16, 2025 | SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows... |
| CVE-2025-53092 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfigura... |
| CVE-2025-25298 | MEDIUM | 5.3 | 0.4% | Oct 16, 2025 | Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum passwor... |
| CVE-2025-9559 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inter... |
| CVE-2025-62493 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect... |
| CVE-2025-62492 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation o... |
| CVE-2025-55035 | MEDIUM | 6.1 | 0.3% | Oct 16, 2025 | Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a se... |
| CVE-2025-11842 | MEDIUM | 6.3 | 0.4% | Oct 16, 2025 | A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function ... |
| CVE-2025-11840 | MEDIUM | 5.5 | 0.3% | Oct 16, 2025 | A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. E... |
| CVE-2025-61540 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php. |
| CVE-2025-61539 | MEDIUM | 6.1 | 0.2% | Oct 16, 2025 | Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php. |
| CVE-2025-41254 | MEDIUM | 4.3 | 0.3% | Oct 16, 2025 | STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized me... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now