2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26782 | HIGH | 7.5 | 0.5% | Oct 20, 2025 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210... |
| CVE-2025-26781 | HIGH | 7.5 | 0.5% | Oct 20, 2025 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210... |
| CVE-2025-10678 | CRITICAL | 9.3 | 0.4% | Oct 20, 2025 | NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin accoun... |
| CVE-2025-8884 | MEDIUM | 5.5 | 0.2% | Oct 20, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Pri... |
| CVE-2025-61456 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoin... |
| CVE-2025-61417 | HIGH | 8.8 | 0.5% | Oct 20, 2025 | Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Att... |
| CVE-2025-57738 | HIGH | 7.2 | 23.1% | Oct 20, 2025 | Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide cus... |
| CVE-2025-54957 | CRITICAL | 9.8 | 1.6% | Oct 20, 2025 | An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+... |
| CVE-2025-41390 | HIGH | 7.8 | 0.3% | Oct 20, 2025 | An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A s... |
| CVE-2025-61455 | CRITICAL | 9.8 | 0.5% | Oct 20, 2025 | SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The... |
| CVE-2025-11680 | MEDIUM | 5.9 | 0.4% | Oct 20, 2025 | Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during ... |
| CVE-2025-11679 | MEDIUM | 5.9 | 0.4% | Oct 20, 2025 | Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled du... |
| CVE-2025-11678 | HIGH | 7.5 | 0.3% | Oct 20, 2025 | Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS fla... |
| CVE-2025-11677 | MEDIUM | 6.3 | 0.4% | Oct 20, 2025 | Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker... |
| CVE-2025-61454 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoi... |
| CVE-2025-56224 | HIGH | 8.1 | 0.4% | Oct 20, 2025 | A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to by... |
| CVE-2025-56223 | HIGH | 7.5 | 0.4% | Oct 20, 2025 | A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Den... |
| CVE-2025-56219 | HIGH | 7.1 | 0.3% | Oct 20, 2025 | Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limitin... |
| CVE-2025-8349 | MEDIUM | 5.3 | 0.5% | Oct 20, 2025 | Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute Java... |
| CVE-2025-57837 | LOW | 2.9 | 0.2% | Oct 20, 2025 | Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affe... |
| CVE-2025-41028 | CRITICAL | 9.3 | 0.4% | Oct 20, 2025 | A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to r... |
| CVE-2025-61932 | CRITICAL | 9.8 | 2.7% | Oct 20, 2025 | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of... |
| CVE-2025-57839 | MEDIUM | 4 | 0.2% | Oct 20, 2025 | Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect ser... |
| CVE-2025-57838 | MEDIUM | 4 | 0.2% | Oct 20, 2025 | Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may af... |
| CVE-2025-31342 | CRITICAL | 9.3 | 0.5% | Oct 20, 2025 | An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now