2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12280 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the ... |
| CVE-2025-41384 | MEDIUM | 6.1 | 0.2% | Oct 27, 2025 | Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute... |
| CVE-2025-12279 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | A vulnerability has been found in code-projects Client Details System 1.0. This vulnerability affects unknown code of th... |
| CVE-2025-11248 | MEDIUM | 4.3 | 0.5% | Oct 27, 2025 | ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging ... |
| CVE-2025-12269 | MEDIUM | 5.4 | 0.3% | Oct 27, 2025 | A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unkno... |
| CVE-2025-12267 | MEDIUM | 4.3 | 0.3% | Oct 27, 2025 | A flaw has been found in abhicodebox ModernShop 20250922. This issue affects some unknown processing of the file /search... |
| CVE-2025-12266 | MEDIUM | 6.3 | 0.3% | Oct 27, 2025 | A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vuln... |
| CVE-2025-12264 | MEDIUM | 5.1 | 0.2% | Oct 27, 2025 | A security flaw has been discovered in Wisencode up to 20251012. Affected by this vulnerability is an unknown functional... |
| CVE-2025-46583 | MEDIUM | 5.3 | 0.4% | Oct 27, 2025 | There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the inpu... |
| CVE-2025-12250 | MEDIUM | 4.7 | 0.5% | Oct 27, 2025 | A flaw has been found in OpenWGA 7.11.12 Build 737. This affects an unknown function of the file WGA.File of the compone... |
| CVE-2025-12080 | MEDIUM | 6.9 | 0.1% | Oct 27, 2025 | On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SE... |
| CVE-2025-12249 | MEDIUM | 6.3 | 0.3% | Oct 27, 2025 | A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. The impacted element is an unknown function... |
| CVE-2025-12246 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/... |
| CVE-2025-12245 | MEDIUM | 5.3 | 0.3% | Oct 27, 2025 | A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunica... |
| CVE-2025-12244 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A vulnerability was determined in code-projects Simple E-Banking System 1.0. This affects an unknown part of the file /e... |
| CVE-2025-12231 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown functi... |
| CVE-2025-12230 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the f... |
| CVE-2025-12229 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of ... |
| CVE-2025-12228 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown functi... |
| CVE-2025-12227 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown func... |
| CVE-2025-11154 | MEDIUM | 5.4 | 0.1% | Oct 27, 2025 | The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handl... |
| CVE-2025-58918 | MEDIUM | 4.3 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Waituk Entrada theme allows Cross Site Request Forgery.This issue aff... |
| CVE-2025-48088 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm_Force U... |
| CVE-2025-12207 | MEDIUM | 5.5 | 0.2% | Oct 27, 2025 | A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the c... |
| CVE-2025-12206 | MEDIUM | 5.5 | 0.2% | Oct 27, 2025 | A flaw has been found in Kamailio 5.5. The impacted element is the function rve_is_constant of the file src/core/rvalue.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now