2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41064 | CRITICAL | 9.3 | 0.4% | Oct 2, 2025 | Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as... |
| CVE-2025-9697 | CRITICAL | 9.8 | 0.3% | Oct 2, 2025 | The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a... |
| CVE-2025-11221 | CRITICAL | 9.4 | 0.3% | Oct 2, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangero... |
| CVE-2025-61588 | CRITICAL | 9.3 | 0.4% | Oct 2, 2025 | RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture.... |
| CVE-2025-59951 | CRITICAL | 9.1 | 4.7% | Oct 1, 2025 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The offici... |
| CVE-2025-59681 | CRITICAL | 9.8 | 0.6% | Oct 1, 2025 | An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), Query... |
| CVE-2025-8679 | CRITICAL | 9.8 | 0.3% | Oct 1, 2025 | In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure... |
| CVE-2025-61045 | CRITICAL | 9.8 | 1.5% | Oct 1, 2025 | TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i... |
| CVE-2025-61044 | CRITICAL | 9.8 | 1.0% | Oct 1, 2025 | TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName param... |
| CVE-2025-61622 | CRITICAL | 9.8 | 41.3% | Oct 1, 2025 | Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from... |
| CVE-2025-10659 | CRITICAL | 9.8 | 1.2% | Sep 30, 2025 | The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that... |
| CVE-2025-56513 | CRITICAL | 9.8 | 0.4% | Sep 30, 2025 | NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An a... |
| CVE-2025-10725 | CRITICAL | 9.9 | 0.7% | Sep 30, 2025 | A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for... |
| CVE-2025-7493 | CRITICAL | 9.1 | 0.5% | Sep 30, 2025 | A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE... |
| CVE-2025-34217 | CRITICAL | 9.8 | 0.7% | Sep 30, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumente... |
| CVE-2025-9762 | CRITICAL | 9.8 | 0.7% | Sep 30, 2025 | The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-8625 | CRITICAL | 9.8 | 0.6% | Sep 30, 2025 | The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function ... |
| CVE-2025-8120 | CRITICAL | 9.8 | 0.5% | Sep 30, 2025 | Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remo... |
| CVE-2025-7065 | CRITICAL | 9.8 | 0.6% | Sep 30, 2025 | Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remo... |
| CVE-2025-7063 | CRITICAL | 9.8 | 0.6% | Sep 30, 2025 | Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remot... |
| CVE-2025-61584 | CRITICAL | 9.3 | 0.3% | Sep 30, 2025 | serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions th... |
| CVE-2025-59954 | CRITICAL | 9.8 | 0.5% | Sep 30, 2025 | Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote ... |
| CVE-2025-11148 | CRITICAL | 9.8 | 1.4% | Sep 30, 2025 | All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool tha... |
| CVE-2025-59937 | CRITICAL | 9.1 | 0.5% | Sep 29, 2025 | go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of ... |
| CVE-2025-54875 | CRITICAL | 9.8 | 0.5% | Sep 29, 2025 | FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now