2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52650 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0 |
| CVE-2025-41089 | MEDIUM | 4.8 | 0.3% | Oct 10, 2025 | Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user in... |
| CVE-2025-41088 | MEDIUM | 5.1 | 0.3% | Oct 10, 2025 | Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. T... |
| CVE-2025-37727 | MEDIUM | 5.7 | 0.2% | Oct 10, 2025 | Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preco... |
| CVE-2025-25018 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS) |
| CVE-2025-25017 | MEDIUM | 6.1 | 0.3% | Oct 10, 2025 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS) |
| CVE-2025-40640 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du... |
| CVE-2025-62292 | MEDIUM | 4.3 | 0.2% | Oct 10, 2025 | In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/... |
| CVE-2025-21070 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-o... |
| CVE-2025-21065 | MEDIUM | 6.6 | 0.2% | Oct 10, 2025 | Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands o... |
| CVE-2025-21064 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data. |
| CVE-2025-21063 | MEDIUM | 4.6 | 0.2% | Oct 10, 2025 | Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16... |
| CVE-2025-21061 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access se... |
| CVE-2025-21060 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access ba... |
| CVE-2025-21059 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung He... |
| CVE-2025-21054 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local at... |
| CVE-2025-21050 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across mult... |
| CVE-2025-21049 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive inform... |
| CVE-2025-21047 | MEDIUM | 6.8 | 0.2% | Oct 10, 2025 | Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged API... |
| CVE-2025-21045 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to acce... |
| CVE-2025-21044 | MEDIUM | 4.4 | 0.1% | Oct 10, 2025 | Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write o... |
| CVE-2025-10124 | MEDIUM | 4.5 | 0.2% | Oct 10, 2025 | The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode... |
| CVE-2025-11570 | MEDIUM | 4.6 | 0.2% | Oct 10, 2025 | Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XS... |
| CVE-2025-11450 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor... |
| CVE-2025-11449 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now