2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62508 | MEDIUM | 6.5 | 0.4% | Oct 17, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulne... |
| CVE-2025-11914 | HIGH | 7.5 | 0.8% | Oct 17, 2025 | A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function ... |
| CVE-2025-62511 | MEDIUM | 6.3 | 0.1% | Oct 17, 2025 | yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 ... |
| CVE-2025-11925 | MEDIUM | 6.1 | 0.2% | Oct 17, 2025 | Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially all... |
| CVE-2025-11913 | MEDIUM | 6.5 | 0.8% | Oct 17, 2025 | A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is ... |
| CVE-2025-11912 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file ... |
| CVE-2025-11911 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of t... |
| CVE-2025-11910 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the funct... |
| CVE-2025-62505 | LOW | 3 | 0.3% | Oct 17, 2025 | LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-... |
| CVE-2025-56320 | MEDIUM | 5.4 | 0.4% | Oct 17, 2025 | CobbleStone Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its cha... |
| CVE-2025-56316 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remo... |
| CVE-2025-56221 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brut... |
| CVE-2025-56218 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a c... |
| CVE-2025-34282 | CRITICAL | 9.1 | 1.7% | Oct 17, 2025 | ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload ... |
| CVE-2025-34281 | MEDIUM | 5.4 | 0.3% | Oct 17, 2025 | ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Galle... |
| CVE-2025-11909 | HIGH | 8.8 | 0.4% | Oct 17, 2025 | A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the functi... |
| CVE-2025-11908 | HIGH | 8.8 | 0.5% | Oct 17, 2025 | A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the f... |
| CVE-2025-62430 | MEDIUM | 5.4 | 0.2% | Oct 17, 2025 | ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site ... |
| CVE-2025-62424 | MEDIUM | 6.5 | 0.9% | Oct 17, 2025 | ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/templa... |
| CVE-2025-62422 | HIGH | 8.8 | 0.5% | Oct 17, 2025 | DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datas... |
| CVE-2025-62421 | MEDIUM | 5.4 | 0.3% | Oct 17, 2025 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scrip... |
| CVE-2025-62420 | HIGH | 8.8 | 0.9% | Oct 17, 2025 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vuln... |
| CVE-2025-62419 | HIGH | 7.5 | 0.4% | Oct 17, 2025 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vuln... |
| CVE-2025-60514 | MEDIUM | 6.5 | 0.3% | Oct 17, 2025 | Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts. |
| CVE-2025-57164 | MEDIUM | 6.5 | 0.6% | Oct 17, 2025 | Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now