2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61926 | MEDIUM | 4.6 | 0.4% | Oct 9, 2025 | Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Rev... |
| CVE-2025-62240 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, a... |
| CVE-2025-61783 | MEDIUM | 6.3 | 0.5% | Oct 9, 2025 | Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, t... |
| CVE-2025-43296 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeepe... |
| CVE-2025-35061 | MEDIUM | 5.9 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker t... |
| CVE-2025-35060 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to u... |
| CVE-2025-35059 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl... |
| CVE-2025-35058 | MEDIUM | 5.9 | 0.4% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NI... |
| CVE-2025-35057 | MEDIUM | 6 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NI... |
| CVE-2025-35056 | MEDIUM | 5 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and... |
| CVE-2025-35054 | MEDIUM | 5.3 | 0.1% | Oct 9, 2025 | Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>... |
| CVE-2025-35053 | MEDIUM | 6.4 | 0.4% | Oct 9, 2025 | Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedP... |
| CVE-2025-35052 | MEDIUM | 6.3 | 0.4% | Oct 9, 2025 | Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values ... |
| CVE-2025-55200 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a St... |
| CVE-2025-60267 | MEDIUM | 6.5 | 0.2% | Oct 9, 2025 | In xckk v9.6, there is a SQL injection vulnerability in which the cond parameter in notice/list is not securely filtered... |
| CVE-2025-11550 | MEDIUM | 6.5 | 0.9% | Oct 9, 2025 | A vulnerability was found in Tenda W12 3.0.0.6(3948). The impacted element is the function wifiScheduledSet of the file ... |
| CVE-2025-60304 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | code-projects Simple Scheduling System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Subject Description field... |
| CVE-2025-60266 | MEDIUM | 6.5 | 0.2% | Oct 9, 2025 | In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in address/list is not securely filt... |
| CVE-2025-60010 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenti... |
| CVE-2025-60009 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-60006 | MEDIUM | 5.3 | 1.0% | Oct 9, 2025 | Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vu... |
| CVE-2025-60002 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-60001 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-60000 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-59999 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now