2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54658 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2025-53951 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2025-53950 | MEDIUM | 6 | 0.2% | Oct 16, 2025 | An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's O... |
| CVE-2025-46752 | MEDIUM | 4.4 | 0.1% | Oct 16, 2025 | A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 al... |
| CVE-2025-11839 | MEDIUM | 5.5 | 0.3% | Oct 16, 2025 | A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Perf... |
| CVE-2025-9955 | MEDIUM | 5.7 | 0.2% | Oct 16, 2025 | An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission res... |
| CVE-2025-9804 | MEDIUM | 6.5 | 0.5% | Oct 16, 2025 | An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in ... |
| CVE-2025-9152 | CRITICAL | 9.8 | 0.7% | Oct 16, 2025 | An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorizatio... |
| CVE-2025-10611 | CRITICAL | 9.8 | 0.8% | Oct 16, 2025 | Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks ... |
| CVE-2025-3930 | MEDIUM | 6.3 | 0.6% | Oct 16, 2025 | Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, ... |
| CVE-2025-6338 | CRITICAL | 9.2 | 0.4% | Oct 16, 2025 | There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of S... |
| CVE-2025-58426 | MEDIUM | 5.3 | 0.2% | Oct 16, 2025 | desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious... |
| CVE-2025-58079 | MEDIUM | 5.3 | 0.3% | Oct 16, 2025 | Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker... |
| CVE-2025-55072 | MEDIUM | 5.4 | 0.3% | Oct 16, 2025 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaS... |
| CVE-2025-54859 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaS... |
| CVE-2025-54760 | MEDIUM | 5.4 | 0.3% | Oct 16, 2025 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaS... |
| CVE-2025-52583 | MEDIUM | 6.1 | 0.3% | Oct 16, 2025 | Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a... |
| CVE-2025-24833 | MEDIUM | 5.4 | 0.3% | Oct 16, 2025 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary... |
| CVE-2025-61581 | HIGH | 7.5 | 0.7% | Oct 16, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This... |
| CVE-2025-58115 | MEDIUM | 6.1 | 0.2% | Oct 16, 2025 | ChatLuck contains a cross-site scripting vulnerability in Guest User Sign-up. If exploited, an arbitrary script may be e... |
| CVE-2025-58075 | HIGH | 8.1 | 0.3% | Oct 16, 2025 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo... |
| CVE-2025-58073 | HIGH | 8.1 | 0.4% | Oct 16, 2025 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to jo... |
| CVE-2025-54539 | CRITICAL | 9.8 | 2.0% | Oct 16, 2025 | A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all... |
| CVE-2025-54499 | LOW | 3.7 | 0.2% | Oct 16, 2025 | Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comp... |
| CVE-2025-54461 | MEDIUM | 6.9 | 0.3% | Oct 16, 2025 | ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now