2025 CVE Vulnerabilities
45,212 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62509 | HIGH | 8.1 | 0.3% | Oct 20, 2025 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version... |
| CVE-2025-55086 | CRITICAL | 9.8 | 0.4% | Oct 20, 2025 | In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there ... |
| CVE-2025-47902 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Pro... |
| CVE-2025-47901 | HIGH | 8.8 | 1.6% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti... |
| CVE-2025-47900 | HIGH | 8.8 | 1.6% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti... |
| CVE-2025-3465 | HIGH | 8.2 | 0.2% | Oct 20, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB C... |
| CVE-2025-11979 | MEDIUM | 6.5 | 0.2% | Oct 20, 2025 | An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation... |
| CVE-2025-9574 | CRITICAL | 10 | 0.8% | Oct 20, 2025 | Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects ... |
| CVE-2025-6515 | MEDIUM | 6.8 | 0.3% | Oct 20, 2025 | The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographical... |
| CVE-2025-62429 | HIGH | 7.2 | 0.8% | Oct 20, 2025 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbi... |
| CVE-2025-60856 | MEDIUM | 6.8 | 0.3% | Oct 20, 2025 | Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attack... |
| CVE-2025-48025 | MEDIUM | 4.3 | 0.3% | Oct 20, 2025 | In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000,... |
| CVE-2025-40017 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix memory leak by freeing untracked p... |
| CVE-2025-40016 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Mark invalid entities with id UVC_... |
| CVE-2025-40015 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: stm32-csi: Fix dereference before NULL check... |
| CVE-2025-40013 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: audioreach: fix potential null pointer ... |
| CVE-2025-40012 | HIGH | 7.8 | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix warning in smc_rx_splice() when callin... |
| CVE-2025-40011 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix null dereference in hdmi teardown ... |
| CVE-2025-40010 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: afs: Fix potential null pointer dereference in afs_... |
| CVE-2025-40009 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: check p->vec_buf for NULL When t... |
| CVE-2025-40008 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: kmsan: fix out-of-bounds access to shadow memory R... |
| CVE-2025-40007 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfs: fix reference leak Commit 20d72b00ca81 ("ne... |
| CVE-2025-40006 | HIGH | 7.8 | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix folio is still mapped when deleted ... |
| CVE-2025-40005 | MEDIUM | 5.5 | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle ... |
| CVE-2025-26782 | HIGH | 7.5 | 0.5% | Oct 20, 2025 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now