2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12476 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-63622 | CRITICAL | 9.8 | 0.3% | Oct 29, 2025 | A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the ... |
| CVE-2025-4665 | CRITICAL | 9.6 | 0.3% | Oct 29, 2025 | WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injectio... |
| CVE-2025-64095 | CRITICAL | 9.8 | 44.7% | Oct 28, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1... |
| CVE-2025-62368 | CRITICAL | 9 | 1.4% | Oct 28, 2025 | Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerabilit... |
| CVE-2025-43017 | CRITICAL | 9.8 | 0.2% | Oct 28, 2025 | HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which ... |
| CVE-2025-61235 | CRITICAL | 9.1 | 0.4% | Oct 28, 2025 | An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted,... |
| CVE-2025-12424 | CRITICAL | 9.8 | 0.3% | Oct 28, 2025 | Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-60355 | CRITICAL | 9.8 | 0.5% | Oct 28, 2025 | zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. |
| CVE-2025-12422 | CRITICAL | 9.8 | 0.4% | Oct 28, 2025 | Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affec... |
| CVE-2025-36386 | CRITICAL | 9.8 | 0.5% | Oct 28, 2025 | IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authen... |
| CVE-2025-61128 | CRITICAL | 9.1 | 0.7% | Oct 28, 2025 | Stack-based buffer overflow vulnerability in WAVLINK QUANTUM D3G/WL-WN530HG3 firmware M30HG3_V240730, and possibly other... |
| CVE-2025-61043 | CRITICAL | 9.1 | 0.4% | Oct 28, 2025 | An out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper... |
| CVE-2025-12380 | CRITICAL | 9.8 | 0.3% | Oct 28, 2025 | Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or bro... |
| CVE-2025-9313 | CRITICAL | 9.3 | 0.5% | Oct 28, 2025 | An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants ful... |
| CVE-2025-40074 | CRITICAL | 9.8 | 0.2% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrli... |
| CVE-2025-12378 | CRITICAL | 9.8 | 0.5% | Oct 28, 2025 | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown pr... |
| CVE-2025-12339 | CRITICAL | 9.8 | 0.4% | Oct 28, 2025 | A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some... |
| CVE-2025-12338 | CRITICAL | 9.8 | 0.4% | Oct 28, 2025 | A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown ... |
| CVE-2025-12337 | CRITICAL | 9.8 | 0.4% | Oct 28, 2025 | A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part o... |
| CVE-2025-12336 | CRITICAL | 9.8 | 0.4% | Oct 28, 2025 | A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unkn... |
| CVE-2025-12325 | CRITICAL | 9.8 | 0.5% | Oct 27, 2025 | A vulnerability has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the f... |
| CVE-2025-12316 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the f... |
| CVE-2025-12315 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /... |
| CVE-2025-12314 | CRITICAL | 9.8 | 0.3% | Oct 27, 2025 | A vulnerability was found in code-projects Food Ordering System 1.0. The impacted element is an unknown function of the ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now