2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-55097MEDIUM6.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-55096MEDIUM6.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-55094HIGH7.5In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...
CVE-2025-55087HIGH7.5In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an ou...
CVE-2025-55093MEDIUM5.3In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...
CVE-2025-55092MEDIUM5.3In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a p...
CVE-2025-11849CRITICAL9.3Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1....
CVE-2025-6950CRITICAL9.9An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. Th...
CVE-2025-6949CRITICAL9.3An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou...
CVE-2025-11900CRITICAL9.8The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to...
CVE-2025-11899CRITICAL9.2Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remot...
CVE-2025-11898HIGH8.7Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers t...
CVE-2025-6894MEDIUM5.3An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou...
CVE-2025-6893CRITICAL9.3An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou...
CVE-2025-6892HIGH8.7An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw i...
CVE-2025-62506HIGH8.1MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege es...
CVE-2025-62504HIGH7.5Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain...
CVE-2025-11896LOW2.1In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stac...
CVE-2025-11864HIGH7.3A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply...
CVE-2025-61554MEDIUM5.5A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-0...
CVE-2025-60358MEDIUM5.5radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
CVE-2025-62428HIGH8.8Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host ...
CVE-2025-62427HIGH8.7The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request For...
CVE-2025-62425HIGH8.3MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and ...
CVE-2025-62423HIGH7.2ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now