2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8414 | CRITICAL | 9.4 | 0.2% | Oct 17, 2025 | Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the ... |
| CVE-2025-62353 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary lo... |
| CVE-2025-60279 | CRITICAL | 9.6 | 0.4% | Oct 17, 2025 | A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users... |
| CVE-2025-57567 | CRITICAL | 9.1 | 0.9% | Oct 17, 2025 | A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file l... |
| CVE-2025-49655 | CRITICAL | 9.8 | 0.7% | Oct 17, 2025 | Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not inc... |
| CVE-2025-55100 | CRITICAL | 9.1 | 0.5% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-11849 | CRITICAL | 9.3 | 0.9% | Oct 17, 2025 | Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.... |
| CVE-2025-6950 | CRITICAL | 9.9 | 0.7% | Oct 17, 2025 | An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. Th... |
| CVE-2025-6949 | CRITICAL | 9.3 | 0.5% | Oct 17, 2025 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou... |
| CVE-2025-11900 | CRITICAL | 9.8 | 1.8% | Oct 17, 2025 | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to... |
| CVE-2025-11899 | CRITICAL | 9.2 | 0.6% | Oct 17, 2025 | Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remot... |
| CVE-2025-6893 | CRITICAL | 9.3 | 0.6% | Oct 17, 2025 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou... |
| CVE-2025-62586 | CRITICAL | 9.8 | 0.7% | Oct 16, 2025 | OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress ver... |
| CVE-2025-61922 | CRITICAL | 9.1 | 0.5% | Oct 16, 2025 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and ... |
| CVE-2025-34516 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an... |
| CVE-2025-34515 | CRITICAL | 9.8 | 7.3% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in... |
| CVE-2025-34513 | CRITICAL | 9.8 | 7.7% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_... |
| CVE-2025-9152 | CRITICAL | 9.8 | 0.7% | Oct 16, 2025 | An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorizatio... |
| CVE-2025-10611 | CRITICAL | 9.8 | 0.8% | Oct 16, 2025 | Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks ... |
| CVE-2025-6338 | CRITICAL | 9.2 | 0.4% | Oct 16, 2025 | There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of S... |
| CVE-2025-54539 | CRITICAL | 9.8 | 2.0% | Oct 16, 2025 | A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all... |
| CVE-2025-41019 | CRITICAL | 9.3 | 0.3% | Oct 16, 2025 | SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete... |
| CVE-2025-41018 | CRITICAL | 9.8 | 0.4% | Oct 16, 2025 | SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete d... |
| CVE-2025-62583 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment. |
| CVE-2025-55089 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now