2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3356 | CRITICAL | 9.8 | 0.4% | Oct 30, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t... |
| CVE-2025-12516 | CRITICAL | 9.8 | 0.3% | Oct 30, 2025 | Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12515 | CRITICAL | 9.8 | 0.3% | Oct 30, 2025 | Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-43027 | CRITICAL | 9.8 | 0.3% | Oct 30, 2025 | A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attac... |
| CVE-2025-50739 | CRITICAL | 9.8 | 0.6% | Oct 30, 2025 | iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization. |
| CVE-2025-53883 | CRITICAL | 9.3 | 0.3% | Oct 30, 2025 | A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run ar... |
| CVE-2025-54469 | CRITICAL | 9.9 | 0.4% | Oct 30, 2025 | A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_... |
| CVE-2025-40099 | CRITICAL | 9.4 | 0.2% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed... |
| CVE-2025-11202 | CRITICAL | 9.8 | 2.9% | Oct 29, 2025 | win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-11201 | CRITICAL | 9.8 | 27.1% | Oct 29, 2025 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows... |
| CVE-2025-11200 | CRITICAL | 9.8 | 1.5% | Oct 29, 2025 | MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp... |
| CVE-2025-64103 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has... |
| CVE-2025-64102 | CRITICAL | 9.8 | 0.4% | Oct 29, 2025 | Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an ... |
| CVE-2025-12478 | CRITICAL | 9.8 | 0.2% | Oct 29, 2025 | Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12477 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12476 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-63622 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the ... |
| CVE-2025-4665 | CRITICAL | 9.6 | 0.3% | Oct 29, 2025 | WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injectio... |
| CVE-2025-64095 | CRITICAL | 9.8 | 44.7% | Oct 28, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1... |
| CVE-2025-62368 | CRITICAL | 9 | 1.4% | Oct 28, 2025 | Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerabilit... |
| CVE-2025-43017 | CRITICAL | 9.8 | 0.2% | Oct 28, 2025 | HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which ... |
| CVE-2025-61235 | CRITICAL | 9.1 | 0.4% | Oct 28, 2025 | An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted,... |
| CVE-2025-12424 | CRITICAL | 9.8 | 0.3% | Oct 28, 2025 | Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-60355 | CRITICAL | 9.8 | 0.5% | Oct 28, 2025 | zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. |
| CVE-2025-12422 | CRITICAL | 9.8 | 0.4% | Oct 28, 2025 | Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now