2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62796 | MEDIUM | 5.8 | 0.3% | Oct 28, 2025 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Versions 1.7.7 through 2.0.1 allow ... |
| CVE-2025-62794 | LOW | 3.8 | 0.1% | Oct 28, 2025 | GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced s... |
| CVE-2025-62727 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthent... |
| CVE-2025-62368 | CRITICAL | 9 | 1.4% | Oct 28, 2025 | Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerabilit... |
| CVE-2025-61598 | MEDIUM | 5.3 | 0.3% | Oct 28, 2025 | Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response he... |
| CVE-2025-43017 | CRITICAL | 9.8 | 0.2% | Oct 28, 2025 | HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which ... |
| CVE-2025-11375 | MEDIUM | 6.5 | 0.4% | Oct 28, 2025 | Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum... |
| CVE-2025-11374 | MEDIUM | 6.5 | 0.4% | Oct 28, 2025 | Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect C... |
| CVE-2025-62367 | MEDIUM | 4.8 | 0.2% | Oct 28, 2025 | Taiga is an open source project management platform. In versions 6.8.3 and earlier, Taiga API is vulnerable to time-base... |
| CVE-2025-61235 | CRITICAL | 9.1 | 0.4% | Oct 28, 2025 | An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted,... |
| CVE-2025-59837 | HIGH | 7.2 | 0.3% | Oct 28, 2025 | Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy doma... |
| CVE-2025-27093 | MEDIUM | 6.3 | 0.2% | Oct 28, 2025 | Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in ... |
| CVE-2025-40843 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
| CVE-2025-12425 | HIGH | 7.8 | 0.2% | Oct 28, 2025 | Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12424 | CRITICAL | 9.8 | 0.3% | Oct 28, 2025 | Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12423 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.... |
| CVE-2025-61080 | MEDIUM | 5.4 | 0.2% | Oct 28, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Clear2Pay Bank Visibility Application - Paym... |
| CVE-2025-60805 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive... |
| CVE-2025-60800 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to acce... |
| CVE-2025-60355 | CRITICAL | 9.8 | 0.5% | Oct 28, 2025 | zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. |
| CVE-2025-60354 | HIGH | 7.5 | 0.2% | Oct 28, 2025 | Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot. |
| CVE-2025-12422 | CRITICAL | 9.8 | 0.4% | Oct 28, 2025 | Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affec... |
| CVE-2025-54605 | HIGH | 7.5 | 0.4% | Oct 28, 2025 | Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2). |
| CVE-2025-54604 | HIGH | 7.5 | 0.4% | Oct 28, 2025 | Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2). |
| CVE-2025-61155 | MEDIUM | 5.5 | 0.3% | Oct 28, 2025 | The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now