2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12004 | CRITICAL | 10 | 0.3% | Oct 21, 2025 | Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Ext... |
| CVE-2025-10916 | CRITICAL | 9.1 | 0.3% | Oct 21, 2025 | The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path valid... |
| CVE-2025-7851 | CRITICAL | 9.8 | 0.6% | Oct 21, 2025 | An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. |
| CVE-2025-6542 | CRITICAL | 9.8 | 0.9% | Oct 21, 2025 | An arbitrary OS command may be executed on the product by a remote unauthenticated attacker. |
| CVE-2025-61303 | CRITICAL | 9.8 | 0.4% | Oct 20, 2025 | Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability... |
| CVE-2025-8053 | CRITICAL | 9.1 | 0.2% | Oct 20, 2025 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-55086 | CRITICAL | 9.8 | 0.4% | Oct 20, 2025 | In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there ... |
| CVE-2025-9574 | CRITICAL | 10 | 0.8% | Oct 20, 2025 | Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects ... |
| CVE-2025-10678 | CRITICAL | 9.3 | 0.4% | Oct 20, 2025 | NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin accoun... |
| CVE-2025-54957 | CRITICAL | 9.8 | 1.6% | Oct 20, 2025 | An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+... |
| CVE-2025-61455 | CRITICAL | 9.8 | 0.5% | Oct 20, 2025 | SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The... |
| CVE-2025-41028 | CRITICAL | 9.3 | 0.4% | Oct 20, 2025 | A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to r... |
| CVE-2025-61932 | CRITICAL | 9.8 | 2.7% | Oct 20, 2025 | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of... |
| CVE-2025-31342 | CRITICAL | 9.3 | 0.5% | Oct 20, 2025 | An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services... |
| CVE-2025-11948 | CRITICAL | 9.8 | 0.9% | Oct 20, 2025 | Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthent... |
| CVE-2025-11943 | CRITICAL | 9.8 | 0.7% | Oct 19, 2025 | A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality ... |
| CVE-2025-11942 | CRITICAL | 9.8 | 1.1% | Oct 19, 2025 | A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing ... |
| CVE-2025-11391 | CRITICAL | 9.8 | 0.9% | Oct 18, 2025 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads d... |
| CVE-2025-62650 | CRITICAL | 9.9 | 0.5% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for... |
| CVE-2025-62645 | CRITICAL | 9.9 | 0.7% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker t... |
| CVE-2025-62515 | CRITICAL | 9.8 | 0.8% | Oct 17, 2025 | pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class ... |
| CVE-2025-56316 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remo... |
| CVE-2025-56221 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brut... |
| CVE-2025-56218 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a c... |
| CVE-2025-34282 | CRITICAL | 9.1 | 1.7% | Oct 17, 2025 | ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now