2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59957 | HIGH | 7 | 0.2% | Oct 9, 2025 | An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series... |
| CVE-2025-56426 | MEDIUM | 6.5 | 0.4% | Oct 9, 2025 | An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, s... |
| CVE-2025-52961 | HIGH | 7.1 | 0.4% | Oct 9, 2025 | An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivit... |
| CVE-2025-52960 | HIGH | 8.2 | 0.3% | Oct 9, 2025 | A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol (SIP) ALG of Juniper... |
| CVE-2025-11198 | HIGH | 8.5 | 0.3% | Oct 9, 2025 | A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allow... |
| CVE-2025-10284 | CRITICAL | 9.6 | 0.7% | Oct 9, 2025 | BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arb... |
| CVE-2025-10283 | CRITICAL | 9.6 | 0.4% | Oct 9, 2025 | BBOT's gitdumper module could be abused to execute commands through a malicious git repository. |
| CVE-2025-10282 | MEDIUM | 4.7 | 0.2% | Oct 9, 2025 | BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious form... |
| CVE-2025-10281 | MEDIUM | 4.7 | 0.2% | Oct 9, 2025 | BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious f... |
| CVE-2025-56683 | CRITICAL | 9.6 | 0.4% | Oct 9, 2025 | A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to ... |
| CVE-2025-45095 | HIGH | 7.3 | 0.3% | Oct 9, 2025 | Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCISer... |
| CVE-2025-39664 | MEDIUM | 6.5 | 0.6% | Oct 9, 2025 | Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows auth... |
| CVE-2025-32919 | HIGH | 7.8 | 0.2% | Oct 9, 2025 | Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Esca... |
| CVE-2025-32916 | MEDIUM | 4.3 | 0.2% | Oct 9, 2025 | Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p4... |
| CVE-2025-62228 | HIGH | 8.8 | 0.4% | Oct 9, 2025 | Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted databas... |
| CVE-2025-36225 | MEDIUM | 4.3 | 0.2% | Oct 9, 2025 | IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user d... |
| CVE-2025-36171 | MEDIUM | 4.9 | 0.3% | Oct 9, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly vali... |
| CVE-2025-11561 | HIGH | 8.8 | 0.8% | Oct 9, 2025 | A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems.... |
| CVE-2025-39963 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring: fix incorrect io_kiocb reference in io_li... |
| CVE-2025-39962 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix untrusted unsigned subtract Fix the fol... |
| CVE-2025-39961 | MEDIUM | 4.7 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase p... |
| CVE-2025-39960 | HIGH | 7.8 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: gpiolib: acpi: initialize acpi_gpio_info struct Si... |
| CVE-2025-10240 | HIGH | 8.8 | 0.3% | Oct 9, 2025 | A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a mali... |
| CVE-2025-10239 | HIGH | 7.2 | 0.3% | Oct 9, 2025 | In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privilege... |
| CVE-2025-9371 | MEDIUM | 6.4 | 0.2% | Oct 9, 2025 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now