2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12365 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12304 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affe... |
| CVE-2025-61795 | MEDIUM | 5.3 | 1.1% | Oct 27, 2025 | Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits)... |
| CVE-2025-60983 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Reflected Cross Site Scripting vulnerability in Rubikon Banking Solution 4.0.3 in the "Search For Customers Information"... |
| CVE-2025-60982 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object r... |
| CVE-2025-54965 | MEDIUM | 6.1 | 0.2% | Oct 27, 2025 | An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize... |
| CVE-2025-12303 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of ... |
| CVE-2025-12302 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown functi... |
| CVE-2025-12300 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown process... |
| CVE-2025-54970 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests... |
| CVE-2025-54969 | MEDIUM | 6.1 | 0.1% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protec... |
| CVE-2025-54967 | MEDIUM | 6.5 | 0.3% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An att... |
| CVE-2025-12299 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown... |
| CVE-2025-12298 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the fil... |
| CVE-2025-12297 | MEDIUM | 4.3 | 0.3% | Oct 27, 2025 | A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.... |
| CVE-2025-60791 | MEDIUM | 6.2 | 0.1% | Oct 27, 2025 | Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application lea... |
| CVE-2025-12291 | MEDIUM | 4.7 | 0.3% | Oct 27, 2025 | A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an u... |
| CVE-2025-10023 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-36121 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML... |
| CVE-2025-12351 | MEDIUM | 6.8 | 0.2% | Oct 27, 2025 | Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker cou... |
| CVE-2025-12290 | MEDIUM | 4.3 | 0.3% | Oct 27, 2025 | A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall Syste... |
| CVE-2025-12289 | MEDIUM | 4.3 | 0.3% | Oct 27, 2025 | A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Af... |
| CVE-2025-50055 | MEDIUM | 6.4 | 0.2% | Oct 27, 2025 | Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 throu... |
| CVE-2025-12282 | MEDIUM | 4.8 | 0.3% | Oct 27, 2025 | A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function o... |
| CVE-2025-12281 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now