2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62708 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability... |
| CVE-2025-62707 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability... |
| CVE-2025-62706 | MEDIUM | 6.5 | 0.4% | Oct 22, 2025 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF... |
| CVE-2025-62705 | MEDIUM | 4.9 | 0.3% | Oct 22, 2025 | OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not ... |
| CVE-2025-62617 | HIGH | 7.2 | 0.4% | Oct 22, 2025 | Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerabilit... |
| CVE-2025-62614 | HIGH | 8.7 | 0.5% | Oct 22, 2025 | BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an... |
| CVE-2025-62613 | MEDIUM | 6.9 | 1.1% | Oct 22, 2025 | VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to b... |
| CVE-2025-62612 | MEDIUM | 5.3 | 0.2% | Oct 22, 2025 | FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link i... |
| CVE-2025-62611 | HIGH | 8.2 | 0.4% | Oct 22, 2025 | aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings ... |
| CVE-2025-62610 | HIGH | 8.1 | 0.4% | Oct 22, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4... |
| CVE-2025-62513 | HIGH | 7.5 | 0.3% | Oct 22, 2025 | OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log expe... |
| CVE-2025-62247 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 20... |
| CVE-2025-62248 | MEDIUM | 4.8 | 0.2% | Oct 22, 2025 | A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Porta... |
| CVE-2025-58712 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file... |
| CVE-2025-60343 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial ... |
| CVE-2025-60342 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. ... |
| CVE-2025-60341 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set... |
| CVE-2025-60340 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial o... |
| CVE-2025-60339 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to ca... |
| CVE-2025-60337 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan fun... |
| CVE-2025-60336 | HIGH | 7.5 | 1.7% | Oct 22, 2025 | A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to caus... |
| CVE-2025-24934 | MEDIUM | 5.4 | 0.2% | Oct 22, 2025 | Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. ... |
| CVE-2025-22178 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a... |
| CVE-2025-22177 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a... |
| CVE-2025-22176 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now