2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36172 | MEDIUM | 5.4 | 0.1% | Nov 3, 2025 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0... |
| CVE-2025-11193 | MEDIUM | 6.8 | 0.1% | Nov 3, 2025 | A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application... |
| CVE-2025-63293 | MEDIUM | 6.5 | 0.4% | Nov 3, 2025 | FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user ... |
| CVE-2025-12657 | MEDIUM | 5.5 | 0.3% | Nov 3, 2025 | The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them i... |
| CVE-2025-63593 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2025-8558 | MEDIUM | 5.4 | 0.5% | Nov 3, 2025 | Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allo... |
| CVE-2025-50363 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name... |
| CVE-2025-10280 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels includin... |
| CVE-2025-63450 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php. |
| CVE-2025-63449 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php. |
| CVE-2025-63448 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1. |
| CVE-2025-63447 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php. |
| CVE-2025-63446 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php. |
| CVE-2025-36092 | MEDIUM | 6.5 | 0.4% | Nov 3, 2025 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of ... |
| CVE-2025-36091 | MEDIUM | 4.3 | 0.3% | Nov 3, 2025 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards t... |
| CVE-2025-63443 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter. |
| CVE-2025-63442 | MEDIUM | 4.6 | 0.2% | Nov 3, 2025 | Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. T... |
| CVE-2025-60892 | MEDIUM | 6.8 | 0.1% | Nov 3, 2025 | An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-... |
| CVE-2025-45663 | MEDIUM | 6.5 | 0.3% | Nov 3, 2025 | An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure. |
| CVE-2025-29699 | MEDIUM | 6.5 | 0.3% | Nov 3, 2025 | NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function. |
| CVE-2025-64294 | MEDIUM | 5.3 | 0.2% | Nov 3, 2025 | Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Co... |
| CVE-2025-12626 | MEDIUM | 4.3 | 0.3% | Nov 3, 2025 | A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects... |
| CVE-2025-12616 | MEDIUM | 5.9 | 0.5% | Nov 3, 2025 | A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onp... |
| CVE-2025-6988 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a... |
| CVE-2025-12137 | MEDIUM | 4.9 | 0.4% | Nov 1, 2025 | The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Re... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now