2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56801 | MEDIUM | 5.1 | 0.1% | Oct 21, 2025 | The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB ... |
| CVE-2025-56800 | MEDIUM | 5.1 | 0.2% | Oct 21, 2025 | Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application impl... |
| CVE-2025-56799 | MEDIUM | 6.5 | 1.2% | Oct 21, 2025 | Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism... |
| CVE-2025-8050 | MEDIUM | 6.5 | 0.3% | Oct 21, 2025 | External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could... |
| CVE-2025-60790 | MEDIUM | 6.5 | 0.4% | Oct 21, 2025 | ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is ... |
| CVE-2025-60507 | HIGH | 8.9 | 0.3% | Oct 21, 2025 | Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role... |
| CVE-2025-60427 | MEDIUM | 6.5 | 0.4% | Oct 21, 2025 | LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can ... |
| CVE-2025-12031 | MEDIUM | 5.3 | 0.2% | Oct 21, 2025 | HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the ... |
| CVE-2025-11757 | HIGH | 8.7 | 0.3% | Oct 21, 2025 | The CloudEdge Cloud does not sanitize the MQTT topic input, which could allow an attacker to leverage the MQTT wildcard ... |
| CVE-2025-62763 | MEDIUM | 5 | 0.2% | Oct 21, 2025 | Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy. |
| CVE-2025-62605 | MEDIUM | 4.3 | 0.3% | Oct 21, 2025 | Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifia... |
| CVE-2025-62598 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ... |
| CVE-2025-62597 | MEDIUM | 6.1 | 0.3% | Oct 21, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ... |
| CVE-2025-62595 | MEDIUM | 6.1 | 0.3% | Oct 21, 2025 | Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to ... |
| CVE-2025-62518 | HIGH | 8.1 | 0.7% | Oct 21, 2025 | astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 co... |
| CVE-2025-60772 | CRITICAL | 9.8 | 0.6% | Oct 21, 2025 | Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthen... |
| CVE-2025-60511 | MEDIUM | 4.3 | 0.2% | Oct 21, 2025 | Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability... |
| CVE-2025-60506 | MEDIUM | 5.4 | 0.2% | Oct 21, 2025 | Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An ... |
| CVE-2025-60500 | HIGH | 7.2 | 0.5% | Oct 21, 2025 | QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass... |
| CVE-2025-11534 | CRITICAL | 9.3 | 0.8% | Oct 21, 2025 | The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could al... |
| CVE-2025-62250 | MEDIUM | 6.5 | 0.2% | Oct 21, 2025 | Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.... |
| CVE-2025-61220 | HIGH | 7.5 | 0.3% | Oct 21, 2025 | The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other... |
| CVE-2025-61194 | MEDIUM | 6.5 | 0.2% | Oct 21, 2025 | daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php. |
| CVE-2025-61181 | MEDIUM | 6.5 | 0.2% | Oct 21, 2025 | daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature. |
| CVE-2025-60751 | HIGH | 7.5 | 2.2% | Oct 21, 2025 | GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now