2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10700 | MEDIUM | 4.3 | 0.2% | Oct 16, 2025 | The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2025-62580 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | ASDA-Soft Stack-based Buffer Overflow Vulnerability |
| CVE-2025-62579 | HIGH | 7.8 | 0.2% | Oct 16, 2025 | ASDA-Soft Stack-based Buffer Overflow Vulnerability |
| CVE-2025-11683 | MEDIUM | 6.5 | 0.2% | Oct 16, 2025 | YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential info... |
| CVE-2025-62375 | MEDIUM | 6.9 | 0.2% | Oct 15, 2025 | go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness ... |
| CVE-2025-43313 | MEDIUM | 5.5 | 0.1% | Oct 15, 2025 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, ... |
| CVE-2025-43282 | MEDIUM | 5.5 | 0.1% | Oct 15, 2025 | A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPad... |
| CVE-2025-43281 | HIGH | 7.8 | 0.1% | Oct 15, 2025 | The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be... |
| CVE-2025-43280 | MEDIUM | 4.7 | 0.2% | Oct 15, 2025 | The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an emai... |
| CVE-2025-11619 | HIGH | 8.8 | 0.2% | Oct 15, 2025 | Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers ... |
| CVE-2025-11568 | MEDIUM | 4.4 | 0.1% | Oct 15, 2025 | A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption for... |
| CVE-2025-11832 | CRITICAL | 9.8 | 0.3% | Oct 15, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Tech... |
| CVE-2025-62410 | CRITICAL | 9.4 | 0.3% | Oct 15, 2025 | In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating unt... |
| CVE-2025-62382 | HIGH | 7.7 | 0.3% | Oct 15, 2025 | Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.2, Frigate'... |
| CVE-2025-62381 | HIGH | 8.3 | 0.5% | Oct 15, 2025 | sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to ... |
| CVE-2025-62371 | HIGH | 7.4 | 0.2% | Oct 15, 2025 | OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSe... |
| CVE-2025-62380 | LOW | 2.9 | 0.4% | Oct 15, 2025 | mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions thr... |
| CVE-2025-62378 | MEDIUM | 6.1 | 0.1% | Oct 15, 2025 | CommandKit is the discord.js meta-framework for building Discord bots. In versions 1.2.0-rc.1 through 1.2.0-rc.11, a log... |
| CVE-2025-58133 | HIGH | 7.5 | 0.3% | Oct 15, 2025 | Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a dis... |
| CVE-2025-58132 | MEDIUM | 6.5 | 1.9% | Oct 15, 2025 | Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of informatio... |
| CVE-2025-54271 | MEDIUM | 5.6 | 0.1% | Oct 15, 2025 | Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Conditio... |
| CVE-2025-20360 | MEDIUM | 5.8 | 0.4% | Oct 15, 2025 | Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,... |
| CVE-2025-20359 | MEDIUM | 6.5 | 0.4% | Oct 15, 2025 | Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,... |
| CVE-2025-20351 | MEDIUM | 6.1 | 0.3% | Oct 15, 2025 | A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon... |
| CVE-2025-20350 | HIGH | 7.5 | 0.4% | Oct 15, 2025 | A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now