2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58084 | MEDIUM | 6.5 | 0.3% | Oct 13, 2025 | Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing ... |
| CVE-2025-62243 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Lif... |
| CVE-2025-61775 | MEDIUM | 6.9 | 0.3% | Oct 13, 2025 | Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unex... |
| CVE-2025-62244 | MEDIUM | 4.3 | 0.3% | Oct 13, 2025 | Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Lif... |
| CVE-2025-39965 | MEDIUM | 5.5 | 0.2% | Oct 13, 2025 | In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.... |
| CVE-2025-39964 | MEDIUM | 5.5 | 0.3% | Oct 13, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_a... |
| CVE-2025-9337 | MEDIUM | 6.8 | 0.1% | Oct 13, 2025 | A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a speciall... |
| CVE-2025-9336 | MEDIUM | 6.8 | 0.1% | Oct 13, 2025 | A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipu... |
| CVE-2025-11184 | MEDIUM | 6.9 | 0.4% | Oct 13, 2025 | Cross-site scripting vulnerability in QGIS QWC2 Registration GUI <=v2025.03.31 allows an authorized attacker to plant ar... |
| CVE-2025-11183 | MEDIUM | 6.9 | 0.4% | Oct 13, 2025 | Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 <2025.08.14 allows an authorized attacker to plant ar... |
| CVE-2025-10720 | MEDIUM | 6.5 | 0.3% | Oct 13, 2025 | The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However... |
| CVE-2025-11674 | MEDIUM | 6.9 | 0.3% | Oct 13, 2025 | SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to... |
| CVE-2025-11672 | MEDIUM | 6.9 | 0.3% | Oct 13, 2025 | Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthentic... |
| CVE-2025-11671 | MEDIUM | 6.9 | 0.3% | Oct 13, 2025 | Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthentic... |
| CVE-2025-10558 | MEDIUM | 6.1 | 0.2% | Oct 13, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows a... |
| CVE-2025-10557 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator ... |
| CVE-2025-10556 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager fro... |
| CVE-2025-10552 | MEDIUM | 6.1 | 0.2% | Oct 13, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an ... |
| CVE-2025-27259 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limite... |
| CVE-2025-9698 | MEDIUM | 6.8 | 0.3% | Oct 13, 2025 | The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow use... |
| CVE-2025-11663 | MEDIUM | 6.1 | 0.2% | Oct 13, 2025 | A weakness has been identified in Campcodes Online Beauty Parlor Management System 1.0. The affected element is an unkno... |
| CVE-2025-31994 | MEDIUM | 4.3 | 0.2% | Oct 13, 2025 | HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious scr... |
| CVE-2025-11655 | MEDIUM | 4.7 | 0.3% | Oct 13, 2025 | A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted elemen... |
| CVE-2025-11650 | MEDIUM | 4 | 0.1% | Oct 12, 2025 | A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the f... |
| CVE-2025-11649 | MEDIUM | 6.3 | 0.1% | Oct 12, 2025 | A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the compon... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now