2025 CVE Vulnerabilities
45,213 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61908 | MEDIUM | 6.5 | 0.5% | Oct 16, 2025 | Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invali... |
| CVE-2025-61907 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to th... |
| CVE-2025-61330 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment... |
| CVE-2025-60641 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexce... |
| CVE-2025-60639 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26). |
| CVE-2025-34519 | HIGH | 7.5 | 0.3% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product ... |
| CVE-2025-34518 | HIGH | 7.5 | 0.6% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_conte... |
| CVE-2025-34517 | HIGH | 7.5 | 0.6% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_cont... |
| CVE-2025-34516 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an... |
| CVE-2025-34515 | CRITICAL | 9.8 | 7.3% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in... |
| CVE-2025-34514 | HIGH | 8.8 | 2.1% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in mul... |
| CVE-2025-34513 | CRITICAL | 9.8 | 7.7% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_... |
| CVE-2025-34512 | MEDIUM | 6.1 | 0.4% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in i... |
| CVE-2025-61789 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with acce... |
| CVE-2025-58051 | MEDIUM | 6.5 | 0.5% | Oct 16, 2025 | Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when impor... |
| CVE-2025-56700 | MEDIUM | 5.4 | 0.2% | Oct 16, 2025 | Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allo... |
| CVE-2025-56699 | MEDIUM | 5.4 | 0.3% | Oct 16, 2025 | SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows... |
| CVE-2025-53092 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfigura... |
| CVE-2025-36128 | HIGH | 7.5 | 0.5% | Oct 16, 2025 | IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of th... |
| CVE-2025-25298 | MEDIUM | 5.3 | 0.4% | Oct 16, 2025 | Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum passwor... |
| CVE-2025-11854 | — | — | — | Oct 16, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22381. Reason: This candidate is a ... |
| CVE-2025-9559 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inter... |
| CVE-2025-62496 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to cr... |
| CVE-2025-62495 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent rep... |
| CVE-2025-62494 | HIGH | 8.8 | 0.5% | Oct 16, 2025 | A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now