2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61589 | MEDIUM | 5.9 | 0.3% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows ... |
| CVE-2025-59536 | HIGH | 8.8 | 29.3% | Oct 3, 2025 | Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the sta... |
| CVE-2025-61847 | — | — | — | Oct 3, 2025 | Rejected reason: Not used |
| CVE-2025-59300 | HIGH | 7.8 | 0.2% | Oct 3, 2025 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta... |
| CVE-2025-59299 | HIGH | 7.8 | 0.1% | Oct 3, 2025 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta... |
| CVE-2025-59298 | HIGH | 7.8 | 0.2% | Oct 3, 2025 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta... |
| CVE-2025-59297 | HIGH | 7.8 | 0.2% | Oct 3, 2025 | Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta... |
| CVE-2025-11241 | MEDIUM | 6.4 | 0.3% | Oct 3, 2025 | The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to ... |
| CVE-2025-10895 | — | — | — | Oct 2, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-61668 | HIGH | 8.7 | 0.4% | Oct 2, 2025 | Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17... |
| CVE-2025-61666 | HIGH | 8.7 | 1.2% | Oct 2, 2025 | Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and n... |
| CVE-2025-61600 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerabil... |
| CVE-2025-61665 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken ... |
| CVE-2025-61606 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open R... |
| CVE-2025-61605 | CRITICAL | 9.8 | 0.4% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL In... |
| CVE-2025-54089 | LOW | 3.4 | 0.2% | Oct 2, 2025 | CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with admin... |
| CVE-2025-54088 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the c... |
| CVE-2025-61604 | HIGH | 7.1 | 0.2% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-S... |
| CVE-2025-61603 | CRITICAL | 9.8 | 0.4% | Oct 2, 2025 | WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability whi... |
| CVE-2025-61595 | HIGH | 8.8 | 0.3% | Oct 2, 2025 | MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4... |
| CVE-2025-54087 | LOW | 2.6 | 0.2% | Oct 2, 2025 | CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with ad... |
| CVE-2025-54086 | LOW | 3.3 | 0.2% | Oct 2, 2025 | CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to vers... |
| CVE-2025-10653 | HIGH | 8.6 | 0.4% | Oct 2, 2025 | An unauthenticated debug port may allow access to the device file system. |
| CVE-2025-59835 | HIGH | 8.6 | 0.4% | Oct 2, 2025 | LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attac... |
| CVE-2025-54315 | HIGH | 7.1 | 0.3% | Oct 2, 2025 | The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now