2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61457 | MEDIUM | 6.1 | 0.3% | Oct 21, 2025 | code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php. |
| CVE-2025-61255 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search pa... |
| CVE-2025-56802 | MEDIUM | 5.1 | 0.1% | Oct 21, 2025 | The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files... |
| CVE-2025-56801 | MEDIUM | 5.1 | 0.1% | Oct 21, 2025 | The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB ... |
| CVE-2025-56800 | MEDIUM | 5.1 | 0.2% | Oct 21, 2025 | Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application impl... |
| CVE-2025-56799 | MEDIUM | 6.5 | 1.2% | Oct 21, 2025 | Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism... |
| CVE-2025-8050 | MEDIUM | 6.5 | 0.3% | Oct 21, 2025 | External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could... |
| CVE-2025-60790 | MEDIUM | 6.5 | 0.4% | Oct 21, 2025 | ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is ... |
| CVE-2025-60427 | MEDIUM | 6.5 | 0.4% | Oct 21, 2025 | LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can ... |
| CVE-2025-12031 | MEDIUM | 5.3 | 0.2% | Oct 21, 2025 | HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the ... |
| CVE-2025-62763 | MEDIUM | 5 | 0.2% | Oct 21, 2025 | Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy. |
| CVE-2025-62605 | MEDIUM | 4.3 | 0.3% | Oct 21, 2025 | Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifia... |
| CVE-2025-62598 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ... |
| CVE-2025-62597 | MEDIUM | 6.1 | 0.3% | Oct 21, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ... |
| CVE-2025-62595 | MEDIUM | 6.1 | 0.3% | Oct 21, 2025 | Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to ... |
| CVE-2025-60511 | MEDIUM | 4.3 | 0.2% | Oct 21, 2025 | Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability... |
| CVE-2025-60506 | MEDIUM | 5.4 | 0.2% | Oct 21, 2025 | Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An ... |
| CVE-2025-62250 | MEDIUM | 6.5 | 0.2% | Oct 21, 2025 | Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.... |
| CVE-2025-61194 | MEDIUM | 6.5 | 0.2% | Oct 21, 2025 | daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php. |
| CVE-2025-61181 | MEDIUM | 6.5 | 0.2% | Oct 21, 2025 | daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature. |
| CVE-2025-60280 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code ... |
| CVE-2025-60934 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Perfor... |
| CVE-2025-60933 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Perf... |
| CVE-2025-60932 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Per... |
| CVE-2025-59438 | MEDIUM | 5.3 | 0.2% | Oct 21, 2025 | Mbed TLS through 3.6.4 has an Observable Timing Discrepancy. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now