2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11899 | CRITICAL | 9.2 | 0.6% | Oct 17, 2025 | Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remot... |
| CVE-2025-6893 | CRITICAL | 9.3 | 0.6% | Oct 17, 2025 | An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou... |
| CVE-2025-62586 | CRITICAL | 9.8 | 0.7% | Oct 16, 2025 | OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress ver... |
| CVE-2025-61922 | CRITICAL | 9.1 | 0.5% | Oct 16, 2025 | PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and ... |
| CVE-2025-34516 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an... |
| CVE-2025-34515 | CRITICAL | 9.8 | 7.3% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in... |
| CVE-2025-34513 | CRITICAL | 9.8 | 7.7% | Oct 16, 2025 | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_... |
| CVE-2025-9152 | CRITICAL | 9.8 | 0.7% | Oct 16, 2025 | An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorizatio... |
| CVE-2025-10611 | CRITICAL | 9.8 | 0.8% | Oct 16, 2025 | Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks ... |
| CVE-2025-6338 | CRITICAL | 9.2 | 0.4% | Oct 16, 2025 | There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of S... |
| CVE-2025-54539 | CRITICAL | 9.8 | 2.0% | Oct 16, 2025 | A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all... |
| CVE-2025-41019 | CRITICAL | 9.3 | 0.3% | Oct 16, 2025 | SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete... |
| CVE-2025-41018 | CRITICAL | 9.8 | 0.4% | Oct 16, 2025 | SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete d... |
| CVE-2025-62583 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment. |
| CVE-2025-55089 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in t... |
| CVE-2025-10850 | CRITICAL | 9.8 | 0.6% | Oct 16, 2025 | The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.... |
| CVE-2025-10742 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin... |
| CVE-2025-11832 | CRITICAL | 9.8 | 0.3% | Oct 15, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Tech... |
| CVE-2025-62410 | CRITICAL | 9.4 | 0.3% | Oct 15, 2025 | In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating unt... |
| CVE-2025-20359 | CRITICAL | 9.1 | 0.4% | Oct 15, 2025 | Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,... |
| CVE-2025-56749 | CRITICAL | 9.4 | 0.5% | Oct 15, 2025 | Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictabl... |
| CVE-2025-53521 | CRITICAL | 9.8 | 2.2% | Oct 15, 2025 | When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Ex... |
| CVE-2025-55081 | CRITICAL | 9.1 | 0.3% | Oct 15, 2025 | In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was... |
| CVE-2025-9967 | CRITICAL | 9.8 | 0.4% | Oct 15, 2025 | The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve... |
| CVE-2025-10294 | CRITICAL | 9.8 | 0.8% | Oct 15, 2025 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now