2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43911 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43906 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43890 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-1826 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, ... |
| CVE-2025-56243 | MEDIUM | 6.1 | 0.2% | Oct 7, 2025 | A Cross-Site Scripting (XSS) vulnerability was found in the register.php page of PuneethReddyHC Event Management System ... |
| CVE-2025-60312 | MEDIUM | 6.1 | 0.3% | Oct 7, 2025 | Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" fie... |
| CVE-2025-53476 | MEDIUM | 5.3 | 0.3% | Oct 7, 2025 | A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5c... |
| CVE-2025-37728 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A ma... |
| CVE-2025-25009 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload. |
| CVE-2025-40888 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. ... |
| CVE-2025-40887 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter... |
| CVE-2025-40885 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input p... |
| CVE-2025-40676 | MEDIUM | 5.3 | 0.2% | Oct 7, 2025 | Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Rese... |
| CVE-2025-40649 | MEDIUM | 5.1 | 0.3% | Oct 7, 2025 | Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infras... |
| CVE-2025-3718 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing valid... |
| CVE-2025-11390 | MEDIUM | 6.1 | 0.3% | Oct 7, 2025 | A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-11360 | MEDIUM | 5.3 | 0.3% | Oct 7, 2025 | A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the ... |
| CVE-2025-10645 | MEDIUM | 5.3 | 0.3% | Oct 7, 2025 | The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ... |
| CVE-2025-7400 | MEDIUM | 6.4 | 0.2% | Oct 7, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featur... |
| CVE-2025-61768 | MEDIUM | 5.1 | 0.3% | Oct 6, 2025 | KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Fo... |
| CVE-2025-43824 | MEDIUM | 5.4 | 0.2% | Oct 6, 2025 | The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 ... |
| CVE-2025-59452 | MEDIUM | 5.8 | 0.4% | Oct 6, 2025 | The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an... |
| CVE-2025-59450 | MEDIUM | 4.3 | 0.1% | Oct 6, 2025 | The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network a... |
| CVE-2025-59449 | MEDIUM | 4.9 | 0.3% | Oct 6, 2025 | The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-ac... |
| CVE-2025-59448 | MEDIUM | 4.7 | 0.2% | Oct 6, 2025 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now