2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34315 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34314 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34313 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34310 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34309 | MEDIUM | 5.4 | 5.0% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34308 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34307 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34306 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34305 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain multiple stored cross-site scripting (XSS) vulnerabilities cause... |
| CVE-2025-34304 | MEDIUM | 6.5 | 0.4% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attac... |
| CVE-2025-34303 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34302 | MEDIUM | 5.4 | 0.5% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-34301 | MEDIUM | 5.4 | 5.0% | Oct 28, 2025 | IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an... |
| CVE-2025-12390 | MEDIUM | 6 | 0.1% | Oct 28, 2025 | A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use... |
| CVE-2025-12103 | MEDIUM | 5 | 0.2% | Oct 28, 2025 | A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a... |
| CVE-2025-40040 | MEDIUM | 5.5 | 0.3% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/ksm: fix flag-dropping behavior in ksm_madvise ... |
| CVE-2025-40039 | MEDIUM | 4.7 | 0.1% | Oct 28, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access... |
| CVE-2025-55758 | MEDIUM | 5.4 | 0.1% | Oct 28, 2025 | Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered. |
| CVE-2025-12344 | MEDIUM | 6.3 | 0.2% | Oct 28, 2025 | A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /... |
| CVE-2025-33133 | MEDIUM | 6.5 | 0.3% | Oct 28, 2025 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authen... |
| CVE-2025-33132 | MEDIUM | 6.5 | 0.3% | Oct 28, 2025 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authen... |
| CVE-2025-33131 | MEDIUM | 6.5 | 0.3% | Oct 28, 2025 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authen... |
| CVE-2025-33126 | MEDIUM | 6.5 | 0.3% | Oct 28, 2025 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.... |
| CVE-2025-12335 | MEDIUM | 6.1 | 0.4% | Oct 28, 2025 | A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown fun... |
| CVE-2025-12332 | MEDIUM | 4.8 | 0.3% | Oct 28, 2025 | A flaw has been found in SourceCodester Student Grades Management System 1.0. This affects the function delete_user of t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now