2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64296 | MEDIUM | 5.3 | 0.2% | Oct 29, 2025 | Missing Authorization vulnerability in Facebook Facebook for WooCommerce facebook-for-woocommerce allows Exploiting Inco... |
| CVE-2025-57931 | MEDIUM | 5.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.Thi... |
| CVE-2025-64094 | MEDIUM | 5.4 | 0.2% | Oct 28, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1... |
| CVE-2025-62802 | MEDIUM | 4.3 | 0.2% | Oct 28, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1... |
| CVE-2025-62800 | MEDIUM | 6.1 | 0.3% | Oct 28, 2025 | FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site sc... |
| CVE-2025-62798 | MEDIUM | 5.4 | 0.2% | Oct 28, 2025 | Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vu... |
| CVE-2025-62796 | MEDIUM | 5.8 | 0.3% | Oct 28, 2025 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Versions 1.7.7 through 2.0.1 allow ... |
| CVE-2025-61598 | MEDIUM | 5.3 | 0.3% | Oct 28, 2025 | Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response he... |
| CVE-2025-11375 | MEDIUM | 6.5 | 0.4% | Oct 28, 2025 | Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum... |
| CVE-2025-11374 | MEDIUM | 6.5 | 0.4% | Oct 28, 2025 | Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect C... |
| CVE-2025-62367 | MEDIUM | 4.8 | 0.2% | Oct 28, 2025 | Taiga is an open source project management platform. In versions 6.8.3 and earlier, Taiga API is vulnerable to time-base... |
| CVE-2025-27093 | MEDIUM | 6.3 | 0.2% | Oct 28, 2025 | Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in ... |
| CVE-2025-61080 | MEDIUM | 5.4 | 0.2% | Oct 28, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Clear2Pay Bank Visibility Application - Paym... |
| CVE-2025-61155 | MEDIUM | 5.5 | 0.3% | Oct 28, 2025 | The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in ... |
| CVE-2025-36085 | MEDIUM | 5.4 | 0.2% | Oct 28, 2025 | IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenti... |
| CVE-2025-36083 | MEDIUM | 5.5 | 0.1% | Oct 28, 2025 | IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to ... |
| CVE-2025-36081 | MEDIUM | 5.3 | 0.2% | Oct 28, 2025 | IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log... |
| CVE-2025-34318 | MEDIUM | 5.1 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34317 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34316 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34315 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34314 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34313 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34310 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34309 | MEDIUM | 5.4 | 5.0% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now