2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61455 | CRITICAL | 9.8 | 0.5% | Oct 20, 2025 | SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The... |
| CVE-2025-41028 | CRITICAL | 9.3 | 0.4% | Oct 20, 2025 | A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to r... |
| CVE-2025-61932 | CRITICAL | 9.8 | 2.7% | Oct 20, 2025 | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of... |
| CVE-2025-31342 | CRITICAL | 9.3 | 0.5% | Oct 20, 2025 | An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services... |
| CVE-2025-11948 | CRITICAL | 9.8 | 0.9% | Oct 20, 2025 | Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthent... |
| CVE-2025-11943 | CRITICAL | 9.8 | 0.7% | Oct 19, 2025 | A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality ... |
| CVE-2025-11942 | CRITICAL | 9.8 | 1.1% | Oct 19, 2025 | A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing ... |
| CVE-2025-11391 | CRITICAL | 9.8 | 0.9% | Oct 18, 2025 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads d... |
| CVE-2025-62650 | CRITICAL | 9.9 | 0.5% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for... |
| CVE-2025-62645 | CRITICAL | 9.9 | 0.7% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker t... |
| CVE-2025-62515 | CRITICAL | 9.8 | 0.8% | Oct 17, 2025 | pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class ... |
| CVE-2025-56316 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remo... |
| CVE-2025-56221 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brut... |
| CVE-2025-56218 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a c... |
| CVE-2025-34282 | CRITICAL | 9.1 | 1.7% | Oct 17, 2025 | ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload ... |
| CVE-2025-8414 | CRITICAL | 9.4 | 0.2% | Oct 17, 2025 | Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the ... |
| CVE-2025-62353 | CRITICAL | 9.8 | 0.6% | Oct 17, 2025 | A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary lo... |
| CVE-2025-60279 | CRITICAL | 9.6 | 0.4% | Oct 17, 2025 | A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users... |
| CVE-2025-57567 | CRITICAL | 9.1 | 0.9% | Oct 17, 2025 | A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file l... |
| CVE-2025-49655 | CRITICAL | 9.8 | 0.7% | Oct 17, 2025 | Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not inc... |
| CVE-2025-55100 | CRITICAL | 9.1 | 0.5% | Oct 17, 2025 | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss... |
| CVE-2025-11849 | CRITICAL | 9.3 | 0.9% | Oct 17, 2025 | Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.... |
| CVE-2025-6950 | CRITICAL | 9.9 | 0.7% | Oct 17, 2025 | An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. Th... |
| CVE-2025-6949 | CRITICAL | 9.3 | 0.5% | Oct 17, 2025 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou... |
| CVE-2025-11900 | CRITICAL | 9.8 | 1.8% | Oct 17, 2025 | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now