2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10928 | MEDIUM | 6.3 | 0.2% | Oct 30, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This is... |
| CVE-2025-10927 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible t... |
| CVE-2025-10926 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field ... |
| CVE-2025-61724 | MEDIUM | 5.3 | 0.5% | Oct 29, 2025 | The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the n... |
| CVE-2025-58189 | MEDIUM | 5.3 | 0.4% | Oct 29, 2025 | When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols... |
| CVE-2025-58186 | MEDIUM | 5.3 | 0.5% | Oct 29, 2025 | Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By s... |
| CVE-2025-58185 | MEDIUM | 5.3 | 0.5% | Oct 29, 2025 | Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion. |
| CVE-2025-58183 | MEDIUM | 4.3 | 0.4% | Oct 29, 2025 | tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A mal... |
| CVE-2025-54549 | MEDIUM | 5.9 | 0.1% | Oct 29, 2025 | Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgra... |
| CVE-2025-54548 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user... |
| CVE-2025-54547 | MEDIUM | 5.3 | 0.1% | Oct 29, 2025 | On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) mult... |
| CVE-2025-47912 | MEDIUM | 5.3 | 0.4% | Oct 29, 2025 | The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component ... |
| CVE-2025-61959 | MEDIUM | 6.9 | 0.2% | Oct 29, 2025 | Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebR... |
| CVE-2025-60320 | MEDIUM | 6.7 | 0.1% | Oct 29, 2025 | memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (... |
| CVE-2025-11466 | MEDIUM | 4.9 | 1.9% | Oct 29, 2025 | Allegra DatabaseBackupBL Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote atta... |
| CVE-2025-61876 | MEDIUM | 5 | 0.2% | Oct 29, 2025 | Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an aut... |
| CVE-2025-64100 | MEDIUM | 6.1 | 0.3% | Oct 29, 2025 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4,... |
| CVE-2025-1549 | MEDIUM | 6.3 | 0.1% | Oct 29, 2025 | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user ... |
| CVE-2025-60898 | MEDIUM | 5.8 | 0.3% | Oct 29, 2025 | An unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 a... |
| CVE-2025-60542 | MEDIUM | 6.5 | 0.2% | Oct 29, 2025 | SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to ... |
| CVE-2025-54384 | MEDIUM | 6.3 | 0.2% | Oct 29, 2025 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4,... |
| CVE-2025-12148 | MEDIUM | 6 | 0.3% | Oct 29, 2025 | In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Ad... |
| CVE-2025-12147 | MEDIUM | 6 | 0.3% | Oct 29, 2025 | In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-value... |
| CVE-2025-64150 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read per... |
| CVE-2025-64149 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attacker... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now