2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62418MEDIUM4.8Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a...
CVE-2025-62417HIGH7.8Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character...
CVE-2025-62416MEDIUM6.8Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SS...
CVE-2025-62415MEDIUM4.8Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a...
CVE-2025-62414MEDIUM4.8Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin...
CVE-2025-61553HIGH8.2An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (...
CVE-2025-61514MEDIUM6.5An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitra...
CVE-2025-60855MEDIUM5.1Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows ...
CVE-2025-34255MEDIUM5.3D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic...
CVE-2025-34254MEDIUM5.3D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic...
CVE-2025-34253MEDIUM5.4D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to imp...
CVE-2025-11853HIGH8.1A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of th...
CVE-2025-11852MEDIUM5.5A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/...
CVE-2025-11493HIGH7.5The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updat...
CVE-2025-11492HIGH7.5In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on...
CVE-2025-62586CRITICAL9.8OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress ver...
CVE-2025-62413MEDIUM6.1MQTTX is an MQTT 5.0 desktop client and MQTT testing tool. A Cross-Site Scripting (XSS) vulnerability was introduced in ...
CVE-2025-62412MEDIUM4.8LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules p...
CVE-2025-62411MEDIUM4.8LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site S...
CVE-2025-62409HIGH7.5Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large request...
CVE-2025-62407MEDIUM6.1Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through t...
CVE-2025-61924LOW3.8PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and...
CVE-2025-61923MEDIUM4.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and...
CVE-2025-61922CRITICAL9.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and ...
CVE-2025-61909MEDIUM4.4Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now