2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34155 | MEDIUM | 6.9 | 0.6% | Oct 23, 2025 | Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authen... |
| CVE-2025-50951 | MEDIUM | 6.5 | 0.2% | Oct 23, 2025 | FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c. |
| CVE-2025-50949 | MEDIUM | 6.5 | 0.2% | Oct 23, 2025 | FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8. |
| CVE-2025-12114 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue af... |
| CVE-2025-56009 | MEDIUM | 5.3 | 0.2% | Oct 23, 2025 | Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take... |
| CVE-2025-56008 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near t... |
| CVE-2025-56007 | MEDIUM | 6.5 | 0.3% | Oct 23, 2025 | CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding addi... |
| CVE-2025-12110 | MEDIUM | 5.4 | 0.3% | Oct 23, 2025 | A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the... |
| CVE-2025-62256 | MEDIUM | 5.3 | 0.4% | Oct 23, 2025 | Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA... |
| CVE-2025-60852 | MEDIUM | 6.5 | 0.4% | Oct 23, 2025 | A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built wi... |
| CVE-2025-53702 | MEDIUM | 6.5 | 0.2% | Oct 23, 2025 | Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same l... |
| CVE-2025-53701 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET re... |
| CVE-2025-1679 | MEDIUM | 4.8 | 0.3% | Oct 23, 2025 | Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attac... |
| CVE-2025-11429 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on ... |
| CVE-2025-8427 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a... |
| CVE-2025-11128 | MEDIUM | 5 | 0.3% | Oct 23, 2025 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2025-10705 | MEDIUM | 5.3 | 0.3% | Oct 23, 2025 | The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver... |
| CVE-2025-62401 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them m... |
| CVE-2025-62400 | MEDIUM | 6.5 | 0.2% | Oct 23, 2025 | Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden g... |
| CVE-2025-62398 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certa... |
| CVE-2025-62397 | MEDIUM | 5.3 | 0.3% | Oct 23, 2025 | The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially ... |
| CVE-2025-62396 | MEDIUM | 5.3 | 0.3% | Oct 23, 2025 | An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings ... |
| CVE-2025-62395 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information fr... |
| CVE-2025-62394 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive u... |
| CVE-2025-62393 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | A flaw was found in the course overview output function where user access permissions were not fully enforced. This coul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now