2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62267 | MEDIUM | 6.1 | 0.2% | Oct 31, 2025 | Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.... |
| CVE-2025-12546 | MEDIUM | 5.4 | 0.3% | Oct 31, 2025 | A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen... |
| CVE-2025-62264 | MEDIUM | 6.1 | 0.2% | Oct 31, 2025 | Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, an... |
| CVE-2025-6075 | MEDIUM | 5.5 | 0.1% | Oct 31, 2025 | If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env... |
| CVE-2025-59501 | MEDIUM | 4.8 | 3.1% | Oct 31, 2025 | Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing o... |
| CVE-2025-12357 | MEDIUM | 6.3 | 0.2% | Oct 31, 2025 | By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker ca... |
| CVE-2025-64387 | MEDIUM | 5.1 | 0.4% | Oct 31, 2025 | The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is i... |
| CVE-2025-61427 | MEDIUM | 6.1 | 0.2% | Oct 31, 2025 | A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execu... |
| CVE-2025-12521 | MEDIUM | 5.3 | 0.2% | Oct 31, 2025 | The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-12460 | MEDIUM | 5.3 | 0.4% | Oct 31, 2025 | An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially craft... |
| CVE-2025-4952 | MEDIUM | 6.8 | 0.1% | Oct 31, 2025 | Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the... |
| CVE-2025-36249 | MEDIUM | 5.3 | 0.1% | Oct 31, 2025 | IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or se... |
| CVE-2025-64368 | MEDIUM | 5.4 | 0.1% | Oct 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issu... |
| CVE-2025-64367 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groun... |
| CVE-2025-64365 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extr... |
| CVE-2025-64362 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen K Ele... |
| CVE-2025-64361 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Con... |
| CVE-2025-64358 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows E... |
| CVE-2025-64357 | MEDIUM | 4.3 | 0.1% | Oct 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allow... |
| CVE-2025-64356 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorre... |
| CVE-2025-64354 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gut... |
| CVE-2025-64351 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows R... |
| CVE-2025-40603 | MEDIUM | 4.5 | 0.4% | Oct 31, 2025 | A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, aut... |
| CVE-2025-11602 | MEDIUM | 6.3 | 0.3% | Oct 31, 2025 | Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obta... |
| CVE-2025-12041 | MEDIUM | 5.3 | 0.2% | Oct 31, 2025 | The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now