2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55097 | MEDIUM | 6.1 | 0.2% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-55096 | MEDIUM | 6.1 | 0.2% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-55094 | HIGH | 7.5 | 0.4% | Oct 17, 2025 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou... |
| CVE-2025-55087 | HIGH | 7.5 | 0.4% | Oct 17, 2025 | In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an ou... |
| CVE-2025-55093 | MEDIUM | 5.3 | 0.3% | Oct 17, 2025 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou... |
| CVE-2025-55092 | MEDIUM | 5.3 | 0.3% | Oct 17, 2025 | In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a p... |
| CVE-2025-11849 | CRITICAL | 9.3 | 0.9% | Oct 17, 2025 | Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.... |
| CVE-2025-6950 | CRITICAL | 9.9 | 0.7% | Oct 17, 2025 | An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. Th... |
| CVE-2025-6949 | CRITICAL | 9.3 | 0.5% | Oct 17, 2025 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou... |
| CVE-2025-11900 | CRITICAL | 9.8 | 1.8% | Oct 17, 2025 | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to... |
| CVE-2025-11899 | CRITICAL | 9.2 | 0.6% | Oct 17, 2025 | Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remot... |
| CVE-2025-11898 | HIGH | 8.7 | 0.8% | Oct 17, 2025 | Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers t... |
| CVE-2025-6894 | MEDIUM | 5.3 | 0.5% | Oct 17, 2025 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou... |
| CVE-2025-6893 | CRITICAL | 9.3 | 0.6% | Oct 17, 2025 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou... |
| CVE-2025-6892 | HIGH | 8.7 | 0.6% | Oct 17, 2025 | An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw i... |
| CVE-2025-62506 | HIGH | 8.1 | 0.5% | Oct 16, 2025 | MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege es... |
| CVE-2025-62504 | HIGH | 7.5 | 0.4% | Oct 16, 2025 | Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain... |
| CVE-2025-11896 | LOW | 2.1 | 0.2% | Oct 16, 2025 | In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stac... |
| CVE-2025-11864 | HIGH | 7.3 | 0.4% | Oct 16, 2025 | A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply... |
| CVE-2025-61554 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-0... |
| CVE-2025-60358 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations. |
| CVE-2025-62428 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host ... |
| CVE-2025-62427 | HIGH | 8.7 | 0.4% | Oct 16, 2025 | The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request For... |
| CVE-2025-62425 | HIGH | 8.3 | 0.4% | Oct 16, 2025 | MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and ... |
| CVE-2025-62423 | HIGH | 7.2 | 0.5% | Oct 16, 2025 | ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now