2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62171 | HIGH | 7.5 | 0.7% | Oct 17, 2025 | ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick ... |
| CVE-2025-62168 | HIGH | 7.5 | 63.3% | Oct 17, 2025 | Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credential... |
| CVE-2025-8414 | CRITICAL | 9.4 | 0.2% | Oct 17, 2025 | Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the ... |
| CVE-2025-62356 | HIGH | 7.5 | 0.6% | Oct 17, 2025 | A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local f... |
| CVE-2025-62353 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary lo... |
| CVE-2025-60279 | CRITICAL | 9.6 | 0.4% | Oct 17, 2025 | A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users... |
| CVE-2025-59043 | HIGH | 7.5 | 0.7% | Oct 17, 2025 | OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects aft... |
| CVE-2025-58747 | MEDIUM | 6.1 | 5.2% | Oct 17, 2025 | Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable t... |
| CVE-2025-57567 | CRITICAL | 9.1 | 0.9% | Oct 17, 2025 | A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file l... |
| CVE-2025-49655 | CRITICAL | 9.8 | 0.7% | Oct 17, 2025 | Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not inc... |
| CVE-2025-26625 | HIGH | 8.6 | 0.7% | Oct 17, 2025 | Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git re... |
| CVE-2025-11905 | HIGH | 8.8 | 0.7% | Oct 17, 2025 | A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the... |
| CVE-2025-60361 | LOW | 3.3 | 0.1% | Oct 17, 2025 | radare2 v5.9.8 and before contains a memory leak in the function bochs_open. |
| CVE-2025-55085 | HIGH | 7.5 | 0.6% | Oct 17, 2025 | In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsi... |
| CVE-2025-48087 | MEDIUM | 6.5 | 0.2% | Oct 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlit... |
| CVE-2025-11904 | HIGH | 7.2 | 0.6% | Oct 17, 2025 | A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/mo... |
| CVE-2025-60360 | MEDIUM | 5.5 | 0.2% | Oct 17, 2025 | radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init. |
| CVE-2025-60359 | MEDIUM | 5.5 | 0.2% | Oct 17, 2025 | radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new. |
| CVE-2025-48044 | HIGH | 8.6 | 0.8% | Oct 17, 2025 | Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated ... |
| CVE-2025-11903 | HIGH | 7.2 | 0.6% | Oct 17, 2025 | A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cm... |
| CVE-2025-11902 | HIGH | 7.2 | 0.6% | Oct 17, 2025 | A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findFie... |
| CVE-2025-11895 | MEDIUM | 4.3 | 0.2% | Oct 17, 2025 | The Binary MLM Plan plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and includ... |
| CVE-2025-55100 | CRITICAL | 9.1 | 0.5% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-55099 | MEDIUM | 6.1 | 0.3% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-55098 | MEDIUM | 6.1 | 0.3% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now