2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62595 | MEDIUM | 6.1 | 0.3% | Oct 21, 2025 | Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to ... |
| CVE-2025-60511 | MEDIUM | 4.3 | 0.2% | Oct 21, 2025 | Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability... |
| CVE-2025-60506 | MEDIUM | 5.4 | 0.2% | Oct 21, 2025 | Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An ... |
| CVE-2025-62250 | MEDIUM | 6.5 | 0.2% | Oct 21, 2025 | Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.... |
| CVE-2025-61194 | MEDIUM | 6.5 | 0.2% | Oct 21, 2025 | daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php. |
| CVE-2025-61181 | MEDIUM | 6.5 | 0.2% | Oct 21, 2025 | daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature. |
| CVE-2025-60280 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code ... |
| CVE-2025-60934 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Perfor... |
| CVE-2025-60933 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Perf... |
| CVE-2025-60932 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Per... |
| CVE-2025-59438 | MEDIUM | 5.3 | 0.2% | Oct 21, 2025 | Mbed TLS through 3.6.4 has an Observable Timing Discrepancy. |
| CVE-2025-57521 | MEDIUM | 6.1 | 0.1% | Oct 21, 2025 | Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application... |
| CVE-2025-56450 | MEDIUM | 6.5 | 0.3% | Oct 21, 2025 | Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter ... |
| CVE-2025-6239 | MEDIUM | 6.5 | 0.9% | Oct 21, 2025 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Di... |
| CVE-2025-7473 | MEDIUM | 5.3 | 0.3% | Oct 21, 2025 | Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. |
| CVE-2025-10612 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Info... |
| CVE-2025-26392 | MEDIUM | 4.6 | 0.2% | Oct 21, 2025 | SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using... |
| CVE-2025-62702 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62701 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62694 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62699 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Transla... |
| CVE-2025-62696 | MEDIUM | 6.9 | 1.2% | Oct 21, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Found... |
| CVE-2025-62695 | MEDIUM | 6.9 | 0.3% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-54764 | MEDIUM | 6.2 | 0.2% | Oct 20, 2025 | Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i... |
| CVE-2025-12001 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now