2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64385 | CRITICAL | 9.2 | 0.5% | Oct 31, 2025 | The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the ... |
| CVE-2025-57108 | CRITICAL | 9.8 | 0.4% | Oct 31, 2025 | Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader.... |
| CVE-2025-6520 | CRITICAL | 9.8 | 0.3% | Oct 31, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BA... |
| CVE-2025-8489 | CRITICAL | 9.8 | 9.1% | Oct 31, 2025 | The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vu... |
| CVE-2025-5397 | CRITICAL | 9.8 | 1.0% | Oct 31, 2025 | The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.... |
| CVE-2025-52665 | CRITICAL | 10 | 41.0% | Oct 31, 2025 | A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access applicat... |
| CVE-2025-48983 | CRITICAL | 9.9 | 0.8% | Oct 31, 2025 | A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the ... |
| CVE-2025-34277 | CRITICAL | 9.8 | 2.0% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID value... |
| CVE-2025-34274 | CRITICAL | 9.8 | 1.9% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs... |
| CVE-2025-34271 | CRITICAL | 9.8 | 0.7% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting ... |
| CVE-2025-3356 | CRITICAL | 9.8 | 0.4% | Oct 30, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t... |
| CVE-2025-12516 | CRITICAL | 9.8 | 0.3% | Oct 30, 2025 | Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12515 | CRITICAL | 9.8 | 0.3% | Oct 30, 2025 | Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-43027 | CRITICAL | 9.8 | 0.3% | Oct 30, 2025 | A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attac... |
| CVE-2025-50739 | CRITICAL | 9.8 | 0.6% | Oct 30, 2025 | iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization. |
| CVE-2025-53883 | CRITICAL | 9.3 | 0.3% | Oct 30, 2025 | A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run ar... |
| CVE-2025-54469 | CRITICAL | 9.9 | 0.4% | Oct 30, 2025 | A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_... |
| CVE-2025-40099 | CRITICAL | 9.4 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed... |
| CVE-2025-11202 | CRITICAL | 9.8 | 2.9% | Oct 29, 2025 | win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-11201 | CRITICAL | 9.8 | 27.1% | Oct 29, 2025 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows... |
| CVE-2025-11200 | CRITICAL | 9.8 | 1.5% | Oct 29, 2025 | MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp... |
| CVE-2025-64103 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has... |
| CVE-2025-64102 | CRITICAL | 9.8 | 0.4% | Oct 29, 2025 | Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an ... |
| CVE-2025-12478 | CRITICAL | 9.8 | 0.2% | Oct 29, 2025 | Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12477 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now