2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60938 | HIGH | 7.5 | 0.6% | Oct 24, 2025 | Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users ... |
| CVE-2025-60936 | MEDIUM | 6.1 | 0.2% | Oct 24, 2025 | Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated atta... |
| CVE-2025-60572 | HIGH | 7.5 | 0.4% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formA... |
| CVE-2025-60571 | HIGH | 7.5 | 0.4% | Oct 24, 2025 | D-Link DIR600LAx FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSe... |
| CVE-2025-60570 | HIGH | 7.5 | 0.4% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formL... |
| CVE-2025-60569 | HIGH | 7.5 | 0.5% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS... |
| CVE-2025-60568 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formA... |
| CVE-2025-56438 | MEDIUM | 6.8 | 0.1% | Oct 24, 2025 | An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically... |
| CVE-2025-43995 | CRITICAL | 9.8 | 0.8% | Oct 24, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An ... |
| CVE-2025-43994 | HIGH | 7.5 | 0.6% | Oct 24, 2025 | Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Fun... |
| CVE-2025-11145 | HIGH | 7.5 | 0.3% | Oct 24, 2025 | Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Informa... |
| CVE-2025-46425 | MEDIUM | 6.5 | 0.3% | Oct 24, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entit... |
| CVE-2025-46185 | MEDIUM | 6.2 | 0.1% | Oct 24, 2025 | An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via... |
| CVE-2025-46183 | HIGH | 8.2 | 0.3% | Oct 24, 2025 | The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker ... |
| CVE-2025-40024 | HIGH | 7.8 | 0.2% | Oct 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: vhost: Take a reference on the task in struct vhost... |
| CVE-2025-40023 | — | — | 0.2% | Oct 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/vf: Don't expose sysfs attributes not applic... |
| CVE-2025-40022 | — | — | 0.2% | Oct 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix incorrect boolean values in af... |
| CVE-2025-40021 | — | — | 0.2% | Oct 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: dynevent: Add a missing lockdown check on ... |
| CVE-2025-40020 | — | — | 0.2% | Oct 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix shift-out-of-bounds issue Expli... |
| CVE-2025-11576 | MEDIUM | 4.3 | 0.3% | Oct 24, 2025 | The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV In... |
| CVE-2025-40019 | — | — | 0.3% | Oct 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-p... |
| CVE-2025-40018 | HIGH | 7.8 | 0.2% | Oct 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns clean... |
| CVE-2025-10861 | HIGH | 7.5 | 0.4% | Oct 24, 2025 | The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr... |
| CVE-2025-5605 | MEDIUM | 5.3 | 0.8% | Oct 24, 2025 | An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor wit... |
| CVE-2025-5350 | MEDIUM | 4.8 | 0.6% | Oct 24, 2025 | SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now