2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61797 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha... |
| CVE-2025-61796 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha... |
| CVE-2025-54272 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha... |
| CVE-2025-54196 | MEDIUM | 4.3 | 0.3% | Oct 14, 2025 | Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerabil... |
| CVE-2025-54267 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an... |
| CVE-2025-54266 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a ... |
| CVE-2025-54265 | MEDIUM | 5.9 | 0.5% | Oct 14, 2025 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an... |
| CVE-2025-62374 | MEDIUM | 6.4 | 0.4% | Oct 14, 2025 | Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, inje... |
| CVE-2025-60540 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF). |
| CVE-2025-60374 | MEDIUM | 6.1 | 0.3% | Oct 14, 2025 | Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScrip... |
| CVE-2025-59429 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior t... |
| CVE-2025-33177 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could all... |
| CVE-2025-54275 | MEDIUM | 5.5 | 0.1% | Oct 14, 2025 | Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could lead to... |
| CVE-2025-8459 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-60537 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows a... |
| CVE-2025-57563 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to rea... |
| CVE-2025-8430 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-59497 | MEDIUM | 4.7 | 0.2% | Oct 14, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny ... |
| CVE-2025-59294 | MEDIUM | 4.6 | 0.6% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to di... |
| CVE-2025-59288 | MEDIUM | 5.3 | 0.2% | Oct 14, 2025 | Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofi... |
| CVE-2025-59284 | MEDIUM | 5.5 | 0.9% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp... |
| CVE-2025-59260 | MEDIUM | 5.5 | 0.4% | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an author... |
| CVE-2025-59259 | MEDIUM | 6.5 | 1.4% | Oct 14, 2025 | Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d... |
| CVE-2025-59258 | MEDIUM | 6.2 | 0.5% | Oct 14, 2025 | Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker... |
| CVE-2025-59257 | MEDIUM | 6.5 | 1.4% | Oct 14, 2025 | Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now