2025 CVE Vulnerabilities
45,210 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12004 | CRITICAL | 10 | 0.3% | Oct 21, 2025 | Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Ext... |
| CVE-2025-11949 | HIGH | 8.7 | 0.4% | Oct 21, 2025 | EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthentic... |
| CVE-2025-10916 | CRITICAL | 9.1 | 0.3% | Oct 21, 2025 | The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path valid... |
| CVE-2025-62702 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62701 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62694 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62699 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Transla... |
| CVE-2025-62696 | MEDIUM | 6.9 | 1.2% | Oct 21, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Found... |
| CVE-2025-62695 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62684 | — | — | — | Oct 21, 2025 | Rejected reason: Not used |
| CVE-2025-62683 | — | — | — | Oct 21, 2025 | Rejected reason: Not used |
| CVE-2025-62682 | — | — | — | Oct 21, 2025 | Rejected reason: Not used |
| CVE-2025-62681 | — | — | — | Oct 21, 2025 | Rejected reason: Not used |
| CVE-2025-62680 | — | — | — | Oct 21, 2025 | Rejected reason: Not used |
| CVE-2025-62679 | — | — | — | Oct 21, 2025 | Rejected reason: Not used |
| CVE-2025-62678 | — | — | — | Oct 21, 2025 | Rejected reason: Not used |
| CVE-2025-62677 | — | — | — | Oct 21, 2025 | Rejected reason: Not used |
| CVE-2025-9133 | HIGH | 8.1 | 5.5% | Oct 21, 2025 | A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series fi... |
| CVE-2025-8078 | HIGH | 7.2 | 1.5% | Oct 21, 2025 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, US... |
| CVE-2025-7851 | CRITICAL | 9.8 | 0.6% | Oct 21, 2025 | An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. |
| CVE-2025-7850 | HIGH | 7.2 | 2.2% | Oct 21, 2025 | A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. |
| CVE-2025-6542 | CRITICAL | 9.8 | 0.9% | Oct 21, 2025 | An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. |
| CVE-2025-6541 | HIGH | 8.8 | 0.6% | Oct 21, 2025 | An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. |
| CVE-2025-54764 | MEDIUM | 6.2 | 0.2% | Oct 20, 2025 | Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i... |
| CVE-2025-12001 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now