2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61685 | MEDIUM | 6.5 | 0.5% | Oct 3, 2025 | Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vuln... |
| CVE-2025-61681 | MEDIUM | 5.4 | 0.2% | Oct 3, 2025 | KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its fi... |
| CVE-2025-61680 | MEDIUM | 6.6 | 0.3% | Oct 3, 2025 | Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0.... |
| CVE-2025-61679 | HIGH | 7.7 | 0.1% | Oct 3, 2025 | Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained... |
| CVE-2025-61677 | LOW | 2.5 | 0.1% | Oct 3, 2025 | DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and belo... |
| CVE-2025-61673 | HIGH | 8.6 | 0.4% | Oct 3, 2025 | Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authent... |
| CVE-2025-43825 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 throug... |
| CVE-2025-61585 | — | — | — | Oct 3, 2025 | Rejected reason: Further research determined the issue is not an independent vulnerability as it originates from Apache ... |
| CVE-2025-59944 | CRITICAL | 9.8 | 0.3% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the wa... |
| CVE-2025-59943 | CRITICAL | 9.8 | 0.4% | Oct 3, 2025 | phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of e... |
| CVE-2025-10696 | MEDIUM | 5.4 | 0.2% | Oct 3, 2025 | OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does no... |
| CVE-2025-10695 | MEDIUM | 5.3 | 0.3% | Oct 3, 2025 | Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied d... |
| CVE-2025-10692 | HIGH | 7.1 | 0.3% | Oct 3, 2025 | The endpoint POST /api/staff/get-new-tickets concatenates the user-controlled parameter departmentId directly into the S... |
| CVE-2025-59829 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission de... |
| CVE-2025-54374 | HIGH | 8.8 | 0.5% | Oct 3, 2025 | Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code... |
| CVE-2025-53354 | MEDIUM | 6.1 | 0.2% | Oct 3, 2025 | NiceGUI is a Python-based UI framework. Versions 2.24.2 and below are at risk for Cross-Site Scripting (XSS) when develo... |
| CVE-2025-49844 | CRITICAL | 9.9 | 86.3% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-57714 | HIGH | 7.8 | 0.2% | Oct 3, 2025 | An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gain... |
| CVE-2025-54154 | MEDIUM | 6.8 | 0.2% | Oct 3, 2025 | An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical a... |
| CVE-2025-54153 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-53595 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-53407 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2025-53406 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2025-52867 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains... |
| CVE-2025-52866 | MEDIUM | 4.9 | 0.3% | Oct 3, 2025 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now