2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58051 | MEDIUM | 6.5 | 0.5% | Oct 16, 2025 | Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when impor... |
| CVE-2025-56700 | MEDIUM | 5.4 | 0.2% | Oct 16, 2025 | Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allo... |
| CVE-2025-56699 | MEDIUM | 5.4 | 0.3% | Oct 16, 2025 | SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows... |
| CVE-2025-53092 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfigura... |
| CVE-2025-25298 | MEDIUM | 5.3 | 0.4% | Oct 16, 2025 | Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum passwor... |
| CVE-2025-9559 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inter... |
| CVE-2025-62493 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect... |
| CVE-2025-62492 | MEDIUM | 6.5 | 0.4% | Oct 16, 2025 | A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation o... |
| CVE-2025-55035 | MEDIUM | 6.1 | 0.3% | Oct 16, 2025 | Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a se... |
| CVE-2025-11842 | MEDIUM | 6.3 | 0.4% | Oct 16, 2025 | A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function ... |
| CVE-2025-11840 | MEDIUM | 5.5 | 0.3% | Oct 16, 2025 | A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. E... |
| CVE-2025-61540 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php. |
| CVE-2025-61539 | MEDIUM | 6.1 | 0.2% | Oct 16, 2025 | Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php. |
| CVE-2025-41254 | MEDIUM | 4.3 | 0.3% | Oct 16, 2025 | STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized me... |
| CVE-2025-36002 | MEDIUM | 5.5 | 0.1% | Oct 16, 2025 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, ... |
| CVE-2025-53950 | MEDIUM | 6 | 0.2% | Oct 16, 2025 | An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's O... |
| CVE-2025-46752 | MEDIUM | 4.4 | 0.1% | Oct 16, 2025 | A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 al... |
| CVE-2025-11839 | MEDIUM | 5.5 | 0.3% | Oct 16, 2025 | A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Perf... |
| CVE-2025-9955 | MEDIUM | 5.7 | 0.2% | Oct 16, 2025 | An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission res... |
| CVE-2025-9804 | MEDIUM | 6.5 | 0.5% | Oct 16, 2025 | An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in ... |
| CVE-2025-3930 | MEDIUM | 6.3 | 0.6% | Oct 16, 2025 | Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, ... |
| CVE-2025-58426 | MEDIUM | 5.3 | 0.2% | Oct 16, 2025 | desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious... |
| CVE-2025-58079 | MEDIUM | 5.3 | 0.3% | Oct 16, 2025 | Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker... |
| CVE-2025-55072 | MEDIUM | 5.4 | 0.3% | Oct 16, 2025 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaS... |
| CVE-2025-54859 | MEDIUM | 4.8 | 0.3% | Oct 16, 2025 | Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaS... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now