2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58152 | MEDIUM | 6.9 | 0.3% | Oct 31, 2025 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection i... |
| CVE-2025-11191 | MEDIUM | 5.3 | 0.3% | Oct 31, 2025 | The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the cr... |
| CVE-2025-11975 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)... |
| CVE-2025-11806 | MEDIUM | 6.4 | 0.2% | Oct 31, 2025 | The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all ver... |
| CVE-2025-48980 | MEDIUM | 6.5 | 0.3% | Oct 31, 2025 | In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split Vie... |
| CVE-2025-27208 | MEDIUM | 6.1 | 1.4% | Oct 31, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker c... |
| CVE-2025-34283 | MEDIUM | 6.5 | 0.9% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Nept... |
| CVE-2025-34278 | MEDIUM | 5.4 | 0.7% | Oct 30, 2025 | Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source... |
| CVE-2025-34273 | MEDIUM | 6.5 | 0.9% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administ... |
| CVE-2025-34272 | MEDIUM | 6.5 | 0.8% | Oct 30, 2025 | In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the applicatio... |
| CVE-2025-34270 | MEDIUM | 4.9 | 0.6% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fa... |
| CVE-2025-34135 | MEDIUM | 4.4 | 0.3% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. ... |
| CVE-2025-62265 | MEDIUM | 5.4 | 0.2% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupp... |
| CVE-2025-57109 | MEDIUM | 6.5 | 0.3% | Oct 30, 2025 | Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When pr... |
| CVE-2025-52180 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated atta... |
| CVE-2025-52179 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated at... |
| CVE-2025-64118 | MEDIUM | 6.1 | 0.1% | Oct 30, 2025 | node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uni... |
| CVE-2025-64116 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts... |
| CVE-2025-64115 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use... |
| CVE-2025-62266 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 20... |
| CVE-2025-56313 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3... |
| CVE-2025-63885 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to execute arbitrary web sc... |
| CVE-2025-60950 | MEDIUM | 6.1 | 0.3% | Oct 30, 2025 | An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to ex... |
| CVE-2025-60319 | MEDIUM | 6.5 | 0.2% | Oct 30, 2025 | PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttac... |
| CVE-2025-46363 | MEDIUM | 4.3 | 0.3% | Oct 30, 2025 | Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative P... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now