2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62788 | HIGH | 7.5 | 0.3% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_ev... |
| CVE-2025-62787 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer ... |
| CVE-2025-61234 | HIGH | 7.5 | 0.3% | Oct 29, 2025 | Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local networ... |
| CVE-2025-60595 | HIGH | 8.2 | 0.3% | Oct 29, 2025 | SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution. |
| CVE-2025-56558 | LOW | 3 | 0.4% | Oct 29, 2025 | The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct v... |
| CVE-2025-1549 | MEDIUM | 6.3 | 0.1% | Oct 29, 2025 | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user ... |
| CVE-2025-12479 | HIGH | 8.8 | 0.2% | Oct 29, 2025 | Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-... |
| CVE-2025-12478 | CRITICAL | 9.8 | 0.2% | Oct 29, 2025 | Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12477 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12476 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-62786 | HIGH | 8.1 | 0.7% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds... |
| CVE-2025-62785 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation ... |
| CVE-2025-60898 | MEDIUM | 5.8 | 0.3% | Oct 29, 2025 | An unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 a... |
| CVE-2025-60542 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to ... |
| CVE-2025-54384 | MEDIUM | 6.3 | 0.2% | Oct 29, 2025 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4,... |
| CVE-2025-12148 | MEDIUM | 6 | 0.3% | Oct 29, 2025 | In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Ad... |
| CVE-2025-12147 | MEDIUM | 6 | 0.3% | Oct 29, 2025 | In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-value... |
| CVE-2025-63622 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the ... |
| CVE-2025-61429 | HIGH | 8.8 | 0.3% | Oct 29, 2025 | An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request... |
| CVE-2025-61156 | HIGH | 7.8 | 0.1% | Oct 29, 2025 | Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privil... |
| CVE-2025-10932 | HIGH | 8.2 | 0.5% | Oct 29, 2025 | Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Trans... |
| CVE-2025-64150 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read per... |
| CVE-2025-64149 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attacker... |
| CVE-2025-64148 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read per... |
| CVE-2025-64147 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now