2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64389 | HIGH | 8.3 | 0.2% | Oct 31, 2025 | The web server of the device performs exchanges of sensitive information in clear text through an insecure protocol. |
| CVE-2025-64388 | CRITICAL | 9.2 | 0.3% | Oct 31, 2025 | Denial of service of the web server through specific requests to this protocol |
| CVE-2025-64387 | MEDIUM | 5.1 | 0.4% | Oct 31, 2025 | The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is i... |
| CVE-2025-64385 | CRITICAL | 9.2 | 0.5% | Oct 31, 2025 | The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the ... |
| CVE-2025-64168 | HIGH | 7.1 | 0.1% | Oct 31, 2025 | Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when ses... |
| CVE-2025-61427 | MEDIUM | 6.1 | 0.2% | Oct 31, 2025 | A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execu... |
| CVE-2025-60749 | HIGH | 7.8 | 0.2% | Oct 31, 2025 | DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe. |
| CVE-2025-57108 | CRITICAL | 9.8 | 0.4% | Oct 31, 2025 | Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader.... |
| CVE-2025-57107 | HIGH | 7.1 | 0.2% | Oct 31, 2025 | Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader... |
| CVE-2025-57106 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerabi... |
| CVE-2025-12501 | HIGH | 7.5 | 0.5% | Oct 31, 2025 | Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-... |
| CVE-2025-64386 | HIGH | 7.7 | 0.3% | Oct 31, 2025 | The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of... |
| CVE-2025-12521 | MEDIUM | 5.3 | 0.2% | Oct 31, 2025 | The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-12460 | MEDIUM | 5.3 | 0.4% | Oct 31, 2025 | An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially craft... |
| CVE-2025-4952 | MEDIUM | 6.8 | 0.1% | Oct 31, 2025 | Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the... |
| CVE-2025-36249 | MEDIUM | 5.3 | 0.1% | Oct 31, 2025 | IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or se... |
| CVE-2025-33003 | HIGH | 7.8 | 0.1% | Oct 31, 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabi... |
| CVE-2025-64368 | MEDIUM | 5.4 | 0.1% | Oct 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issu... |
| CVE-2025-64367 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groun... |
| CVE-2025-64366 | HIGH | 7.6 | 0.3% | Oct 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu... |
| CVE-2025-64365 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extr... |
| CVE-2025-64364 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64363 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-64362 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen K Ele... |
| CVE-2025-64361 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now