2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11020 | HIGH | 8.8 | 0.3% | Oct 2, 2025 | An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly ex... |
| CVE-2025-61855 | — | — | — | Oct 2, 2025 | Rejected reason: Not used |
| CVE-2025-61854 | — | — | — | Oct 2, 2025 | Rejected reason: Not used |
| CVE-2025-61853 | — | — | — | Oct 2, 2025 | Rejected reason: Not used |
| CVE-2025-61852 | — | — | — | Oct 2, 2025 | Rejected reason: Not used |
| CVE-2025-61851 | — | — | — | Oct 2, 2025 | Rejected reason: Not used |
| CVE-2025-61850 | — | — | — | Oct 2, 2025 | Rejected reason: Not used |
| CVE-2025-61849 | — | — | — | Oct 2, 2025 | Rejected reason: Not used |
| CVE-2025-61588 | CRITICAL | 9.3 | 0.4% | Oct 2, 2025 | RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture.... |
| CVE-2025-61583 | MEDIUM | 6.1 | 0.2% | Oct 1, 2025 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability h... |
| CVE-2025-61582 | HIGH | 7.5 | 0.4% | Oct 1, 2025 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been ident... |
| CVE-2025-61587 | MEDIUM | 6.1 | 0.4% | Oct 1, 2025 | Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter o... |
| CVE-2025-59951 | CRITICAL | 9.1 | 4.7% | Oct 1, 2025 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The offici... |
| CVE-2025-54811 | HIGH | 7.1 | 0.2% | Oct 1, 2025 | OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value. This leads to a... |
| CVE-2025-23355 | HIGH | 7.8 | 0.1% | Oct 1, 2025 | NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL hi... |
| CVE-2025-23297 | HIGH | 7.8 | 0.1% | Oct 1, 2025 | NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attac... |
| CVE-2025-59538 | HIGH | 7.5 | 0.5% | Oct 1, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-... |
| CVE-2025-59537 | HIGH | 7.5 | 0.6% | Oct 1, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 throug... |
| CVE-2025-59531 | HIGH | 7.5 | 0.5% | Oct 1, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 throug... |
| CVE-2025-59337 | MEDIUM | 6.8 | 0.3% | Oct 1, 2025 | Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be... |
| CVE-2025-59150 | HIGH | 7.5 | 0.5% | Oct 1, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-57389 | MEDIUM | 5.4 | 0.2% | Oct 1, 2025 | A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 all... |
| CVE-2025-61189 | MEDIUM | 6.3 | 0.2% | Oct 1, 2025 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFil... |
| CVE-2025-61188 | MEDIUM | 6.3 | 0.2% | Oct 1, 2025 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers... |
| CVE-2025-59149 | MEDIUM | 6.2 | 0.2% | Oct 1, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now