2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59988 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-59987 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-59986 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-59985 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-59984 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-59983 | MEDIUM | 6.1 | 0.3% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-59982 | MEDIUM | 6.1 | 0.3% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-59981 | MEDIUM | 6.1 | 0.3% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-59980 | MEDIUM | 6.9 | 0.3% | Oct 9, 2025 | An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, ... |
| CVE-2025-61532 | MEDIUM | 6.1 | 0.3% | Oct 9, 2025 | Cross Site Scripting vulnerability in SVX Portal v.2.7A to execute arbitrary code via the TG parameter on last_heard_pag... |
| CVE-2025-60302 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, t... |
| CVE-2025-60265 | MEDIUM | 6.5 | 0.2% | Oct 9, 2025 | In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in user/list is not securely filtere... |
| CVE-2025-59962 | MEDIUM | 6 | 0.2% | Oct 9, 2025 | An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and J... |
| CVE-2025-59958 | MEDIUM | 6.9 | 0.3% | Oct 9, 2025 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper N... |
| CVE-2025-56426 | MEDIUM | 6.5 | 0.4% | Oct 9, 2025 | An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, s... |
| CVE-2025-10282 | MEDIUM | 4.7 | 0.2% | Oct 9, 2025 | BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious form... |
| CVE-2025-10281 | MEDIUM | 4.7 | 0.2% | Oct 9, 2025 | BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious f... |
| CVE-2025-39664 | MEDIUM | 6.5 | 0.6% | Oct 9, 2025 | Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows auth... |
| CVE-2025-32916 | MEDIUM | 4.3 | 0.2% | Oct 9, 2025 | Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p4... |
| CVE-2025-36225 | MEDIUM | 4.3 | 0.2% | Oct 9, 2025 | IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user d... |
| CVE-2025-36171 | MEDIUM | 4.9 | 0.3% | Oct 9, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly vali... |
| CVE-2025-39961 | MEDIUM | 4.7 | 0.1% | Oct 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase p... |
| CVE-2025-9371 | MEDIUM | 6.4 | 0.2% | Oct 9, 2025 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versi... |
| CVE-2025-2934 | MEDIUM | 6.5 | 0.5% | Oct 9, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, an... |
| CVE-2025-10249 | MEDIUM | 6.5 | 0.3% | Oct 9, 2025 | The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missin... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now