2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61780 | MEDIUM | 5.3 | 0.4% | Oct 10, 2025 | Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclos... |
| CVE-2025-60308 | MEDIUM | 4.1 | 0.2% | Oct 10, 2025 | code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room ... |
| CVE-2025-8887 | MEDIUM | 6.1 | 0.1% | Oct 10, 2025 | Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unautho... |
| CVE-2025-8886 | MEDIUM | 6.7 | 0.2% | Oct 10, 2025 | Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missi... |
| CVE-2025-61319 | MEDIUM | 6.1 | 0.3% | Oct 10, 2025 | ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. Whe... |
| CVE-2025-61152 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature ... |
| CVE-2025-60868 | MEDIUM | 6.5 | 0.2% | Oct 10, 2025 | The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Str... |
| CVE-2025-62239 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and L... |
| CVE-2025-62238 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 th... |
| CVE-2025-62237 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.11... |
| CVE-2025-7781 | MEDIUM | 6.4 | 0.2% | Oct 10, 2025 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘... |
| CVE-2025-7374 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions ... |
| CVE-2025-11579 | MEDIUM | 6.5 | 0.4% | Oct 10, 2025 | github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary siz... |
| CVE-2025-52624 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-... |
| CVE-2025-11190 | MEDIUM | 5.4 | 0.3% | Oct 10, 2025 | The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redire... |
| CVE-2025-52650 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0 |
| CVE-2025-41089 | MEDIUM | 4.8 | 0.3% | Oct 10, 2025 | Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user in... |
| CVE-2025-41088 | MEDIUM | 5.1 | 0.3% | Oct 10, 2025 | Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. T... |
| CVE-2025-37727 | MEDIUM | 5.7 | 0.2% | Oct 10, 2025 | Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preco... |
| CVE-2025-25018 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS) |
| CVE-2025-25017 | MEDIUM | 6.1 | 0.3% | Oct 10, 2025 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS) |
| CVE-2025-40640 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du... |
| CVE-2025-62292 | MEDIUM | 4.3 | 0.2% | Oct 10, 2025 | In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/... |
| CVE-2025-21070 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-o... |
| CVE-2025-21065 | MEDIUM | 6.6 | 0.2% | Oct 10, 2025 | Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now