2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36592 | MEDIUM | 5.4 | 0.2% | Oct 30, 2025 | Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutra... |
| CVE-2025-12517 | MEDIUM | 5.3 | 0.2% | Oct 30, 2025 | Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.... |
| CVE-2025-11998 | MEDIUM | 6.8 | 0.2% | Oct 30, 2025 | The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing ... |
| CVE-2025-5347 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the r... |
| CVE-2025-5343 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the ... |
| CVE-2025-5342 | MEDIUM | 6.5 | 1.0% | Oct 30, 2025 | Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module. |
| CVE-2025-50574 | MEDIUM | 6.1 | 0.3% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in blog-details.php in Hiruna Gallage's Glamour Salon Management System v1 allo... |
| CVE-2025-50736 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause t... |
| CVE-2025-63608 | MEDIUM | 5.4 | 0.2% | Oct 30, 2025 | A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is loc... |
| CVE-2025-10348 | MEDIUM | 5.1 | 0.4% | Oct 30, 2025 | URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account... |
| CVE-2025-10317 | MEDIUM | 5.1 | 0.2% | Oct 30, 2025 | Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft s... |
| CVE-2025-62503 | MEDIUM | 4.6 | 0.4% | Oct 30, 2025 | User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create... |
| CVE-2025-62402 | MEDIUM | 5.4 | 0.5% | Oct 30, 2025 | API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server w... |
| CVE-2025-54941 | MEDIUM | 4.6 | 0.4% | Oct 30, 2025 | An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a... |
| CVE-2025-54471 | MEDIUM | 6.5 | 0.2% | Oct 30, 2025 | NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was repla... |
| CVE-2025-40090 | MEDIUM | 5.5 | 0.1% | Oct 30, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list acc... |
| CVE-2025-11906 | MEDIUM | 6.7 | 0.1% | Oct 30, 2025 | A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect... |
| CVE-2025-11881 | MEDIUM | 5.3 | 0.3% | Oct 30, 2025 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing... |
| CVE-2025-11627 | MEDIUM | 6.5 | 0.3% | Oct 30, 2025 | The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log ... |
| CVE-2025-10008 | MEDIUM | 5.3 | 0.3% | Oct 30, 2025 | The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due... |
| CVE-2025-12475 | MEDIUM | 6.4 | 0.2% | Oct 30, 2025 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsle... |
| CVE-2025-62257 | MEDIUM | 5.3 | 0.4% | Oct 30, 2025 | Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Lifera... |
| CVE-2025-12083 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme ... |
| CVE-2025-10930 | MEDIUM | 4.3 | 0.1% | Oct 30, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects ... |
| CVE-2025-10929 | MEDIUM | 5.3 | 0.3% | Oct 30, 2025 | Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now