2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53092 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfigura... |
| CVE-2025-36128 | HIGH | 7.5 | 0.5% | Oct 16, 2025 | IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of th... |
| CVE-2025-25298 | MEDIUM | 5.3 | 0.4% | Oct 16, 2025 | Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum passwor... |
| CVE-2025-11854 | — | — | — | Oct 16, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22381. Reason: This candidate is a ... |
| CVE-2025-9559 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inter... |
| CVE-2025-62496 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to cr... |
| CVE-2025-62495 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent rep... |
| CVE-2025-62494 | HIGH | 8.8 | 0.5% | Oct 16, 2025 | A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. ... |
| CVE-2025-62493 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect... |
| CVE-2025-62492 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation o... |
| CVE-2025-62491 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list... |
| CVE-2025-62490 | HIGH | 8.8 | 0.4% | Oct 16, 2025 | In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over ... |
| CVE-2025-55035 | MEDIUM | 6.1 | 0.3% | Oct 16, 2025 | Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a se... |
| CVE-2025-11851 | LOW | 3.5 | 0.3% | Oct 16, 2025 | A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set... |
| CVE-2025-11842 | MEDIUM | 6.3 | 0.4% | Oct 16, 2025 | A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function ... |
| CVE-2025-11840 | MEDIUM | 5.5 | 0.3% | Oct 16, 2025 | A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. E... |
| CVE-2025-61543 | HIGH | 7.1 | 0.3% | Oct 16, 2025 | A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses ... |
| CVE-2025-61541 | HIGH | 7.1 | 0.4% | Oct 16, 2025 | Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset l... |
| CVE-2025-61540 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php. |
| CVE-2025-61539 | MEDIUM | 6.1 | 0.2% | Oct 16, 2025 | Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php. |
| CVE-2025-61536 | HIGH | 8.2 | 0.4% | Oct 16, 2025 | FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` he... |
| CVE-2025-41254 | MEDIUM | 4.3 | 0.3% | Oct 16, 2025 | STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized me... |
| CVE-2025-41253 | HIGH | 7.5 | 0.4% | Oct 16, 2025 | The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment var... |
| CVE-2025-36002 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, ... |
| CVE-2025-22381 | HIGH | 8.2 | 0.6% | Oct 16, 2025 | Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to rese... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now