2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47211 | MEDIUM | 4.9 | 0.5% | Oct 3, 2025 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ... |
| CVE-2025-47210 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-46819 | HIGH | 7.1 | 1.0% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-46818 | HIGH | 7.3 | 0.7% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-44014 | HIGH | 8.8 | 0.5% | Oct 3, 2025 | An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun... |
| CVE-2025-44012 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re... |
| CVE-2025-44011 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-44010 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-44009 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-44008 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac... |
| CVE-2025-61593 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI ... |
| CVE-2025-61592 | HIGH | 8.8 | 0.4% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific ... |
| CVE-2025-52653 | MEDIUM | 5.4 | 0.2% | Oct 3, 2025 | HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the exec... |
| CVE-2025-46817 | HIGH | 8.8 | 3.7% | Oct 3, 2025 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user ... |
| CVE-2025-44007 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re... |
| CVE-2025-44006 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re... |
| CVE-2025-33040 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re... |
| CVE-2025-33039 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re... |
| CVE-2025-33034 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-61591 | HIGH | 8.8 | 1.1% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication wit... |
| CVE-2025-61590 | HIGH | 7.5 | 0.5% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (R... |
| CVE-2025-56551 | HIGH | 8.2 | 0.3% | Oct 3, 2025 | An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate lo... |
| CVE-2025-60787 | HIGH | 7.2 | 24.4% | Oct 3, 2025 | MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name... |
| CVE-2025-57423 | MEDIUM | 6.5 | 0.4% | Oct 3, 2025 | A SQL injection vulnerability was discovered in the /articles endpoint of MyClub 0.5, affecting the query parameters Con... |
| CVE-2025-55972 | HIGH | 7.5 | 0.5% | Oct 3, 2025 | A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Deni... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now