2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57349 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable ... |
| CVE-2025-57348 | MEDIUM | 6.5 | 0.4% | Sep 24, 2025 | The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initializatio... |
| CVE-2025-57347 | CRITICAL | 9.8 | 0.5% | Sep 24, 2025 | A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConf... |
| CVE-2025-57330 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in ... |
| CVE-2025-55322 | HIGH | 7.3 | 0.3% | Sep 24, 2025 | Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network. |
| CVE-2025-55178 | MEDIUM | 5.3 | 0.5% | Sep 24, 2025 | Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could pote... |
| CVE-2025-59524 | MEDIUM | 6.1 | 0.3% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow ... |
| CVE-2025-59343 | HIGH | 8.7 | 0.5% | Sep 24, 2025 | tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink... |
| CVE-2025-59305 | HIGH | 7.6 | 0.3% | Sep 24, 2025 | Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated use... |
| CVE-2025-57354 | MEDIUM | 6.5 | 0.5% | Sep 24, 2025 | A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user... |
| CVE-2025-57353 | MEDIUM | 5.3 | 0.3% | Sep 24, 2025 | The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Du... |
| CVE-2025-57352 | MEDIUM | 5.3 | 0.3% | Sep 24, 2025 | A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespa... |
| CVE-2025-57350 | HIGH | 8.6 | 0.3% | Sep 24, 2025 | The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototy... |
| CVE-2025-56241 | HIGH | 7.5 | 6.3% | Sep 24, 2025 | Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the ... |
| CVE-2025-52907 | HIGH | 8.8 | 0.9% | Sep 24, 2025 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affect... |
| CVE-2025-52906 | CRITICAL | 9.8 | 13.2% | Sep 24, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60... |
| CVE-2025-48869 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded res... |
| CVE-2025-48867 | MEDIUM | 4.8 | 0.2% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerabi... |
| CVE-2025-20352 | HIGH | 7.7 | 37.6% | Sep 24, 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa... |
| CVE-2025-20338 | MEDIUM | 6.7 | 0.1% | Sep 24, 2025 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri... |
| CVE-2025-20327 | HIGH | 7.7 | 0.4% | Sep 24, 2025 | A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to... |
| CVE-2025-20316 | MEDIUM | 5.3 | 0.3% | Sep 24, 2025 | A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X... |
| CVE-2025-20315 | HIGH | 8.6 | 0.4% | Sep 24, 2025 | A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unau... |
| CVE-2025-20314 | MEDIUM | 6.7 | 0.1% | Sep 24, 2025 | A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an una... |
| CVE-2025-20313 | MEDIUM | 6.7 | 0.2% | Sep 24, 2025 | Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileg... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now