2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10041 | CRITICAL | 9.8 | 0.9% | Oct 15, 2025 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2025-39975 | CRITICAL | 9.8 | 0.2% | Oct 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix wrong index reference in smb2_comp... |
| CVE-2025-62376 | CRITICAL | 9.5 | 0.6% | Oct 14, 2025 | pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cf... |
| CVE-2025-49553 | CRITICAL | 9.3 | 0.5% | Oct 14, 2025 | Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could ... |
| CVE-2025-34267 | CRITICAL | 9.9 | 6.1% | Oct 14, 2025 | Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code exec... |
| CVE-2025-11736 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionalit... |
| CVE-2025-59287 | CRITICAL | 9.8 | 100.0% | Oct 14, 2025 | Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over ... |
| CVE-2025-55315 | CRITICAL | 9.9 | 66.3% | Oct 14, 2025 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized at... |
| CVE-2025-54603 | CRITICAL | 9 | 0.6% | Oct 14, 2025 | An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creat... |
| CVE-2025-49708 | CRITICAL | 9.9 | 1.1% | Oct 14, 2025 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-11548 | CRITICAL | 9.3 | 0.5% | Oct 14, 2025 | A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the a... |
| CVE-2025-49201 | CRITICAL | 9.8 | 0.6% | Oct 14, 2025 | A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions,... |
| CVE-2025-9064 | CRITICAL | 9.1 | 0.6% | Oct 14, 2025 | A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on th... |
| CVE-2025-9063 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exp... |
| CVE-2025-7328 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing aut... |
| CVE-2025-11721 | CRITICAL | 9.8 | 0.3% | Oct 14, 2025 | Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presu... |
| CVE-2025-11719 | CRITICAL | 9.8 | 0.3% | Oct 14, 2025 | Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caus... |
| CVE-2025-11717 | CRITICAL | 9.1 | 0.2% | Oct 14, 2025 | When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a passwo... |
| CVE-2025-11710 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks... |
| CVE-2025-11709 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipula... |
| CVE-2025-11708 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Th... |
| CVE-2025-10610 | CRITICAL | 9.8 | 0.3% | Oct 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Inf... |
| CVE-2025-40771 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 154... |
| CVE-2025-40765 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected... |
| CVE-2025-46581 | CRITICAL | 9.8 | 0.7% | Oct 14, 2025 | ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now