2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60357 | HIGH | 8.1 | 0.3% | Jul 17, 2026 | AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv... |
| CVE-2025-45870 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet c... |
| CVE-2025-45868 | HIGH | 8.8 | 0.2% | Jul 16, 2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allo... |
| CVE-2025-71388 | HIGH | 7.6 | 0.3% | Jul 16, 2026 | stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission ... |
| CVE-2025-71377 | HIGH | 8.7 | 0.4% | Jul 16, 2026 | stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching me... |
| CVE-2025-65720 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user... |
| CVE-2025-32781 | MEDIUM | 6.5 | — | Jul 15, 2026 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior... |
| CVE-2025-56365 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model co... |
| CVE-2025-56364 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestin... |
| CVE-2025-56363 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevi... |
| CVE-2025-56362 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Lev... |
| CVE-2025-56361 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev... |
| CVE-2025-62826 | MEDIUM | 4.3 | 0.3% | Jul 14, 2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera... |
| CVE-2025-62675 | MEDIUM | 4.3 | 0.2% | Jul 14, 2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera... |
| CVE-2025-53379 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio... |
| CVE-2025-43892 | MEDIUM | 4.3 | 0.3% | Jul 14, 2026 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v... |
| CVE-2025-11698 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerabilit... |
| CVE-2025-12012 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious u... |
| CVE-2025-12011 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to ... |
| CVE-2025-40945 | HIGH | 8.5 | 0.1% | Jul 14, 2026 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1),... |
| CVE-2025-8412 | LOW | 2 | 0.1% | Jul 14, 2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pa... |
| CVE-2025-15665 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Sl... |
| CVE-2025-45869 | HIGH | 7.3 | — | Jul 13, 2026 | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenti... |
| CVE-2025-6784 | HIGH | 8.8 | 0.5% | Jul 11, 2026 | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 ... |
| CVE-2025-5017 | MEDIUM | 4.9 | 0.3% | Jul 11, 2026 | The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now