2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61998 | MEDIUM | 4.8 | 0.2% | Oct 8, 2025 | OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within t... |
| CVE-2025-61997 | MEDIUM | 4.8 | 0.2% | Oct 8, 2025 | OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual... |
| CVE-2025-61996 | MEDIUM | 4.8 | 0.2% | Oct 8, 2025 | OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual... |
| CVE-2025-43822 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP... |
| CVE-2025-11414 | MEDIUM | 5.5 | 0.2% | Oct 7, 2025 | A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry ... |
| CVE-2025-43823 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111,... |
| CVE-2025-11413 | MEDIUM | 5.5 | 0.2% | Oct 7, 2025 | A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elf... |
| CVE-2025-11412 | MEDIUM | 5.5 | 0.2% | Oct 7, 2025 | A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd... |
| CVE-2025-44824 | MEDIUM | 6.5 | 2.7% | Oct 7, 2025 | Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch ser... |
| CVE-2025-43910 | MEDIUM | 4.4 | 0.1% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-36569 | MEDIUM | 6.7 | 0.5% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-36567 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-36566 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-36565 | MEDIUM | 6.7 | 0.2% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-11406 | MEDIUM | 4.3 | 0.2% | Oct 7, 2025 | A security flaw has been discovered in kaifangqian kaifangqian-base up to 7b3faecda13848b3ced6c17c7423b76c5b47b8ab. This... |
| CVE-2025-61776 | MEDIUM | 4.7 | 0.3% | Oct 7, 2025 | Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software ... |
| CVE-2025-45375 | MEDIUM | 4.4 | 0.1% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43934 | MEDIUM | 6 | 0.2% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43913 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43908 | MEDIUM | 6.7 | 0.4% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43907 | MEDIUM | 6.5 | 0.4% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43905 | MEDIUM | 6.5 | 0.3% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-3449 | MEDIUM | 4.2 | 0.2% | Oct 7, 2025 | A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions... |
| CVE-2025-3448 | MEDIUM | 6.1 | 0.2% | Oct 7, 2025 | Reflected cross-site scripting (XSS) vulnerabilities exist in System Diagnostics Manager (SDM) of B&R Automation Runtime... |
| CVE-2025-8291 | MEDIUM | 4.3 | 0.4% | Oct 7, 2025 | The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset val... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now