2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57521 | MEDIUM | 6.1 | 0.1% | Oct 21, 2025 | Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application... |
| CVE-2025-56450 | MEDIUM | 6.5 | 0.3% | Oct 21, 2025 | Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter ... |
| CVE-2025-6239 | MEDIUM | 6.5 | 0.9% | Oct 21, 2025 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Di... |
| CVE-2025-7473 | MEDIUM | 5.3 | 0.3% | Oct 21, 2025 | Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. |
| CVE-2025-10612 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Info... |
| CVE-2025-26392 | MEDIUM | 4.6 | 0.2% | Oct 21, 2025 | SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using... |
| CVE-2025-62702 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62701 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62694 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62699 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Transla... |
| CVE-2025-62696 | MEDIUM | 6.9 | 1.2% | Oct 21, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Found... |
| CVE-2025-62695 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-54764 | MEDIUM | 6.2 | 0.2% | Oct 20, 2025 | Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i... |
| CVE-2025-12001 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B... |
| CVE-2025-11536 | MEDIUM | 5 | 0.2% | Oct 20, 2025 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver... |
| CVE-2025-62657 | MEDIUM | 5.8 | 0.2% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62656 | MEDIUM | 5.8 | 0.2% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-60783 | MEDIUM | 6.5 | 0.2% | Oct 20, 2025 | There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerabilit... |
| CVE-2025-60781 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_nam... |
| CVE-2025-8051 | MEDIUM | 6.5 | 0.4% | Oct 20, 2025 | Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal. The vulnerability could allow a user ... |
| CVE-2025-8048 | MEDIUM | 6.5 | 0.3% | Oct 20, 2025 | External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could a... |
| CVE-2025-62528 | MEDIUM | 5.4 | 0.2% | Oct 20, 2025 | Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ... |
| CVE-2025-62522 | MEDIUM | 6 | 1.0% | Oct 20, 2025 | Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5... |
| CVE-2025-5517 | MEDIUM | 6.8 | 0.3% | Oct 20, 2025 | Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC ... |
| CVE-2025-62700 | MEDIUM | 6.9 | 0.3% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now