2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49090 | HIGH | 7.1 | 0.4% | Oct 2, 2025 | The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient... |
| CVE-2025-32942 | HIGH | 7.2 | 0.2% | Oct 2, 2025 | SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic. |
| CVE-2025-56019 | MEDIUM | 6.5 | 0.3% | Oct 2, 2025 | An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobil... |
| CVE-2025-60663 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan f... |
| CVE-2025-60661 | MEDIUM | 5.3 | 0.4% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWa... |
| CVE-2025-59409 | HIGH | 7.5 | 0.3% | Oct 2, 2025 | Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck... |
| CVE-2025-59407 | CRITICAL | 9.8 | 0.5% | Oct 2, 2025 | The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falco... |
| CVE-2025-59406 | MEDIUM | 6.2 | 0.2% | Oct 2, 2025 | The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow Li... |
| CVE-2025-59405 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and S... |
| CVE-2025-59403 | CRITICAL | 9.8 | 1.0% | Oct 2, 2025 | The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authenticat... |
| CVE-2025-34210 | MEDIUM | 5.5 | 0.1% | Oct 2, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number o... |
| CVE-2025-34208 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords u... |
| CVE-2025-60662 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan... |
| CVE-2025-60660 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan func... |
| CVE-2025-57305 | MEDIUM | 6.5 | 0.4% | Oct 2, 2025 | VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp. |
| CVE-2025-56162 | MEDIUM | 6.5 | 0.5% | Oct 2, 2025 | YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint.... |
| CVE-2025-56161 | HIGH | 7.5 | 0.5% | Oct 2, 2025 | YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment... |
| CVE-2025-56154 | MEDIUM | 6.1 | 0.3% | Oct 2, 2025 | htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The ... |
| CVE-2025-61096 | MEDIUM | 6.5 | 0.2% | Oct 2, 2025 | PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname pa... |
| CVE-2025-61087 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name fi... |
| CVE-2025-60782 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability i... |
| CVE-2025-59774 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59773 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59772 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59771 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now