2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53533 | MEDIUM | 6.1 | 0.6% | Oct 27, 2025 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker bloc... |
| CVE-2025-46602 | MEDIUM | 5.5 | 0.1% | Oct 27, 2025 | Dell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externall... |
| CVE-2025-36170 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This v... |
| CVE-2025-36138 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This v... |
| CVE-2025-32785 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker bloc... |
| CVE-2025-12365 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12304 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affe... |
| CVE-2025-61795 | MEDIUM | 5.3 | 1.1% | Oct 27, 2025 | Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits)... |
| CVE-2025-60983 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Reflected Cross Site Scripting vulnerability in Rubikon Banking Solution 4.0.3 in the "Search For Customers Information"... |
| CVE-2025-60982 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object r... |
| CVE-2025-54965 | MEDIUM | 6.1 | 0.2% | Oct 27, 2025 | An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize... |
| CVE-2025-12303 | MEDIUM | 4.8 | 0.3% | Oct 27, 2025 | A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of ... |
| CVE-2025-12302 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown functi... |
| CVE-2025-12300 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown process... |
| CVE-2025-54970 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests... |
| CVE-2025-54969 | MEDIUM | 6.1 | 0.1% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protec... |
| CVE-2025-54967 | MEDIUM | 6.5 | 0.3% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An att... |
| CVE-2025-12299 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown... |
| CVE-2025-12298 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the fil... |
| CVE-2025-12297 | MEDIUM | 4.3 | 0.3% | Oct 27, 2025 | A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.... |
| CVE-2025-60791 | MEDIUM | 6.2 | 0.1% | Oct 27, 2025 | Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application lea... |
| CVE-2025-12291 | MEDIUM | 4.7 | 0.3% | Oct 27, 2025 | A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an u... |
| CVE-2025-10023 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-36121 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML... |
| CVE-2025-12351 | MEDIUM | 6.8 | 0.2% | Oct 27, 2025 | Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker cou... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now