2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61044 | CRITICAL | 9.8 | 1.0% | Oct 1, 2025 | TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName param... |
| CVE-2025-61622 | CRITICAL | 9.8 | 41.3% | Oct 1, 2025 | Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from... |
| CVE-2025-10659 | CRITICAL | 9.8 | 1.2% | Sep 30, 2025 | The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that... |
| CVE-2025-56513 | CRITICAL | 9.8 | 0.4% | Sep 30, 2025 | NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An a... |
| CVE-2025-10725 | CRITICAL | 9.9 | 0.7% | Sep 30, 2025 | A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for... |
| CVE-2025-7493 | CRITICAL | 9.1 | 0.5% | Sep 30, 2025 | A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE... |
| CVE-2025-34217 | CRITICAL | 9.8 | 0.7% | Sep 30, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumente... |
| CVE-2025-9762 | CRITICAL | 9.8 | 0.7% | Sep 30, 2025 | The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-8625 | CRITICAL | 9.8 | 0.6% | Sep 30, 2025 | The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function ... |
| CVE-2025-8120 | CRITICAL | 9.8 | 0.5% | Sep 30, 2025 | Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remo... |
| CVE-2025-7065 | CRITICAL | 9.8 | 0.6% | Sep 30, 2025 | Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remo... |
| CVE-2025-7063 | CRITICAL | 9.8 | 0.6% | Sep 30, 2025 | Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remot... |
| CVE-2025-61584 | CRITICAL | 9.3 | 0.3% | Sep 30, 2025 | serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions th... |
| CVE-2025-59954 | CRITICAL | 9.8 | 0.5% | Sep 30, 2025 | Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote ... |
| CVE-2025-11148 | CRITICAL | 9.8 | 1.4% | Sep 30, 2025 | All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool tha... |
| CVE-2025-59937 | CRITICAL | 9.1 | 0.5% | Sep 29, 2025 | go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of ... |
| CVE-2025-54875 | CRITICAL | 9.8 | 0.5% | Sep 29, 2025 | FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker ... |
| CVE-2025-54592 | CRITICAL | 9.8 | 0.5% | Sep 29, 2025 | FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during... |
| CVE-2025-57266 | CRITICAL | 9.8 | 0.3% | Sep 29, 2025 | An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthe... |
| CVE-2025-34224 | CRITICAL | 9.1 | 0.9% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version ... |
| CVE-2025-34223 | CRITICAL | 9.8 | 1.2% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version ... |
| CVE-2025-34222 | CRITICAL | 9.1 | 0.5% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version ... |
| CVE-2025-34221 | CRITICAL | 9.8 | 1.4% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.2.169 and Application prior to version 2... |
| CVE-2025-34218 | CRITICAL | 9.8 | 0.9% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version ... |
| CVE-2025-34216 | CRITICAL | 9.8 | 0.8% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now