2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62577 | HIGH | 8.8 | 0.2% | Oct 20, 2025 | ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged ... |
| CVE-2025-40004 | — | — | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/9p: Fix buffer overflow in USB transport layer ... |
| CVE-2025-11948 | CRITICAL | 9.8 | 0.9% | Oct 20, 2025 | Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthent... |
| CVE-2025-11947 | MEDIUM | 4.5 | 0.2% | Oct 19, 2025 | A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the c... |
| CVE-2025-11946 | MEDIUM | 5.4 | 0.3% | Oct 19, 2025 | A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process... |
| CVE-2025-11945 | LOW | 3.5 | 0.3% | Oct 19, 2025 | A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the compo... |
| CVE-2025-11944 | HIGH | 7.2 | 0.5% | Oct 19, 2025 | A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/control... |
| CVE-2025-11943 | CRITICAL | 9.8 | 0.7% | Oct 19, 2025 | A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality ... |
| CVE-2025-11942 | CRITICAL | 9.8 | 1.1% | Oct 19, 2025 | A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing ... |
| CVE-2025-11941 | HIGH | 8.1 | 0.8% | Oct 19, 2025 | A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php... |
| CVE-2025-11940 | HIGH | 7.3 | 0.2% | Oct 19, 2025 | A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of ... |
| CVE-2025-11939 | HIGH | 7.2 | 0.9% | Oct 19, 2025 | A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/Chu... |
| CVE-2025-11938 | HIGH | 8.1 | 0.7% | Oct 19, 2025 | A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/se... |
| CVE-2025-62672 | MEDIUM | 5.3 | 0.5% | Oct 19, 2025 | rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecifie... |
| CVE-2025-47410 | HIGH | 8.8 | 0.3% | Oct 18, 2025 | Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could all... |
| CVE-2025-11926 | MEDIUM | 4.4 | 0.3% | Oct 18, 2025 | The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi... |
| CVE-2025-9890 | HIGH | 8.8 | 0.4% | Oct 18, 2025 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-5555 | HIGH | 7.8 | 0.2% | Oct 18, 2025 | A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in th... |
| CVE-2025-40003 | — | — | 0.2% | Oct 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix use-after-free caused by cyc... |
| CVE-2025-40002 | — | — | 0.2% | Oct 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix use-after-free in tb_dp_dprx_work ... |
| CVE-2025-40001 | — | — | 0.2% | Oct 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: mvsas: Fix use-after-free bugs in mvs_work_qu... |
| CVE-2025-11256 | MEDIUM | 5.3 | 0.3% | Oct 18, 2025 | The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2025-10750 | MEDIUM | 5.3 | 0.4% | Oct 18, 2025 | The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, ... |
| CVE-2025-9562 | MEDIUM | 6.4 | 0.3% | Oct 18, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs... |
| CVE-2025-11741 | MEDIUM | 5.3 | 0.3% | Oct 18, 2025 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now