2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10355 | MEDIUM | 5.1 | 0.3% | Oct 23, 2025 | Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious UR... |
| CVE-2025-41073 | MEDIUM | 6.5 | 0.3% | Oct 23, 2025 | Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated atta... |
| CVE-2025-40643 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du... |
| CVE-2025-9981 | MEDIUM | 4.8 | 0.2% | Oct 23, 2025 | QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with adm... |
| CVE-2025-9980 | MEDIUM | 4.8 | 0.2% | Oct 23, 2025 | QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin p... |
| CVE-2025-10727 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner S... |
| CVE-2025-62499 | MEDIUM | 4.8 | 0.2% | Oct 23, 2025 | Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted in... |
| CVE-2025-54856 | MEDIUM | 4.8 | 0.2% | Oct 23, 2025 | Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored b... |
| CVE-2025-54806 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a... |
| CVE-2025-62820 | MEDIUM | 4.9 | 0.2% | Oct 23, 2025 | Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within t... |
| CVE-2025-48430 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Comm... |
| CVE-2025-48428 | MEDIUM | 6.7 | 0.1% | Oct 23, 2025 | Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated us... |
| CVE-2025-41402 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to e... |
| CVE-2025-35981 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privil... |
| CVE-2025-62710 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initial... |
| CVE-2025-62706 | MEDIUM | 6.5 | 0.4% | Oct 22, 2025 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF... |
| CVE-2025-62705 | MEDIUM | 4.9 | 0.3% | Oct 22, 2025 | OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not ... |
| CVE-2025-62613 | MEDIUM | 6.9 | 1.1% | Oct 22, 2025 | VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to b... |
| CVE-2025-62612 | MEDIUM | 5.3 | 0.2% | Oct 22, 2025 | FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link i... |
| CVE-2025-62247 | MEDIUM | 6.5 | 0.2% | Oct 22, 2025 | Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 20... |
| CVE-2025-62248 | MEDIUM | 4.8 | 0.2% | Oct 22, 2025 | A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Porta... |
| CVE-2025-58712 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file... |
| CVE-2025-24934 | MEDIUM | 5.4 | 0.2% | Oct 22, 2025 | Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. ... |
| CVE-2025-22178 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a... |
| CVE-2025-22177 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now