2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62418 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a... |
| CVE-2025-62417 | HIGH | 7.8 | 0.4% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character... |
| CVE-2025-62416 | MEDIUM | 6.8 | 0.4% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SS... |
| CVE-2025-62415 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a... |
| CVE-2025-62414 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin... |
| CVE-2025-61553 | HIGH | 8.2 | 0.2% | Oct 16, 2025 | An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (... |
| CVE-2025-61514 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitra... |
| CVE-2025-60855 | MEDIUM | 5.1 | 0.1% | Oct 16, 2025 | Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows ... |
| CVE-2025-34255 | MEDIUM | 5.3 | 1.0% | Oct 16, 2025 | D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic... |
| CVE-2025-34254 | MEDIUM | 5.3 | 1.0% | Oct 16, 2025 | D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic... |
| CVE-2025-34253 | MEDIUM | 5.4 | 0.5% | Oct 16, 2025 | D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to imp... |
| CVE-2025-11853 | HIGH | 8.1 | 0.4% | Oct 16, 2025 | A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of th... |
| CVE-2025-11852 | MEDIUM | 5.5 | 0.6% | Oct 16, 2025 | A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/... |
| CVE-2025-11493 | HIGH | 7.5 | 0.2% | Oct 16, 2025 | The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updat... |
| CVE-2025-11492 | HIGH | 7.5 | 0.2% | Oct 16, 2025 | In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on... |
| CVE-2025-62586 | CRITICAL | 9.8 | 0.7% | Oct 16, 2025 | OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress ver... |
| CVE-2025-62413 | MEDIUM | 6.1 | 0.3% | Oct 16, 2025 | MQTTX is an MQTT 5.0 desktop client and MQTT testing tool. A Cross-Site Scripting (XSS) vulnerability was introduced in ... |
| CVE-2025-62412 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules p... |
| CVE-2025-62411 | MEDIUM | 4.8 | 11.6% | Oct 16, 2025 | LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site S... |
| CVE-2025-62409 | HIGH | 7.5 | 0.4% | Oct 16, 2025 | Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large request... |
| CVE-2025-62407 | MEDIUM | 6.1 | 0.2% | Oct 16, 2025 | Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through t... |
| CVE-2025-61924 | LOW | 3.8 | 0.2% | Oct 16, 2025 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and... |
| CVE-2025-61923 | MEDIUM | 4.1 | 0.8% | Oct 16, 2025 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and... |
| CVE-2025-61922 | CRITICAL | 9.1 | 0.5% | Oct 16, 2025 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and ... |
| CVE-2025-61909 | MEDIUM | 4.4 | 0.2% | Oct 16, 2025 | Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now