2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60858 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration... |
| CVE-2025-60349 | HIGH | 7.5 | 0.3% | Oct 28, 2025 | An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E... |
| CVE-2025-56399 | HIGH | 8.8 | 0.5% | Oct 28, 2025 | alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) ... |
| CVE-2025-36386 | CRITICAL | 9.8 | 0.5% | Oct 28, 2025 | IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authen... |
| CVE-2025-34294 | — | — | — | Oct 28, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the behavior originates fr... |
| CVE-2025-61128 | CRITICAL | 9.1 | 0.7% | Oct 28, 2025 | Stack-based buffer overflow vulnerability in WAVLINK QUANTUM D3G/WL-WN530HG3 firmware M30HG3_V240730, and possibly other... |
| CVE-2025-61107 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p... |
| CVE-2025-61106 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_p... |
| CVE-2025-61104 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tl... |
| CVE-2025-61103 | HIGH | 7.5 | 0.6% | Oct 28, 2025 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_l... |
| CVE-2025-61043 | CRITICAL | 9.1 | 0.4% | Oct 28, 2025 | An out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper... |
| CVE-2025-36085 | MEDIUM | 5.4 | 0.2% | Oct 28, 2025 | IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenti... |
| CVE-2025-36083 | MEDIUM | 5.5 | 0.1% | Oct 28, 2025 | IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to ... |
| CVE-2025-36081 | MEDIUM | 5.3 | 0.2% | Oct 28, 2025 | IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log... |
| CVE-2025-34318 | MEDIUM | 5.1 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34317 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34316 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34315 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34314 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34313 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34312 | HIGH | 8.8 | 2.3% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated a... |
| CVE-2025-34311 | HIGH | 8.8 | 13.8% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated a... |
| CVE-2025-34310 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34309 | MEDIUM | 5.4 | 5.0% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34308 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now