2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34308 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34307 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34306 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34305 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain multiple stored cross-site scripting (XSS) vulnerabilities cause... |
| CVE-2025-34304 | MEDIUM | 6.5 | 0.4% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attac... |
| CVE-2025-34303 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34302 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34301 | MEDIUM | 5.4 | 5.0% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-12390 | MEDIUM | 6 | 0.1% | Oct 28, 2025 | A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use... |
| CVE-2025-12103 | MEDIUM | 5 | 0.2% | Oct 28, 2025 | A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a... |
| CVE-2025-40040 | MEDIUM | 5.5 | 0.3% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/ksm: fix flag-dropping behavior in ksm_madvise ... |
| CVE-2025-40039 | MEDIUM | 4.7 | 0.1% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access... |
| CVE-2025-55758 | MEDIUM | 5.4 | 0.1% | Oct 28, 2025 | Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered. |
| CVE-2025-12344 | MEDIUM | 6.3 | 0.2% | Oct 28, 2025 | A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /... |
| CVE-2025-33133 | MEDIUM | 6.5 | 0.3% | Oct 28, 2025 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authen... |
| CVE-2025-33132 | MEDIUM | 6.5 | 0.3% | Oct 28, 2025 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authen... |
| CVE-2025-33131 | MEDIUM | 6.5 | 0.3% | Oct 28, 2025 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authen... |
| CVE-2025-33126 | MEDIUM | 6.5 | 0.3% | Oct 28, 2025 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.... |
| CVE-2025-12335 | MEDIUM | 6.1 | 0.4% | Oct 28, 2025 | A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown fun... |
| CVE-2025-12332 | MEDIUM | 4.8 | 0.3% | Oct 28, 2025 | A flaw has been found in SourceCodester Student Grades Management System 1.0. This affects the function delete_user of t... |
| CVE-2025-62259 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4... |
| CVE-2025-62258 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.... |
| CVE-2025-12334 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/pr... |
| CVE-2025-12333 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A vulnerability has been found in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pa... |
| CVE-2025-62793 | MEDIUM | 6.8 | 0.2% | Oct 27, 2025 | eLabFTW is an open source electronic lab notebook for research labs. The application served uploaded SVG files inline. B... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now