2025 CVE Vulnerabilities
45,327 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-42706 | MEDIUM | 6.5 | 0.2% | Oct 8, 2025 | A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute co... |
| CVE-2025-42701 | MEDIUM | 5.6 | 0.1% | Oct 8, 2025 | A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute... |
| CVE-2025-11485 | MEDIUM | 4.8 | 0.3% | Oct 8, 2025 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user... |
| CVE-2025-60318 | MEDIUM | 6.1 | 0.2% | Oct 8, 2025 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi... |
| CVE-2025-59303 | MEDIUM | 6.4 | 0.2% | Oct 8, 2025 | HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snipp... |
| CVE-2025-36636 | MEDIUM | 4.3 | 0.2% | Oct 8, 2025 | In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticat... |
| CVE-2025-61672 | MEDIUM | 5.3 | 0.4% | Oct 8, 2025 | Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3... |
| CVE-2025-60834 | MEDIUM | 6.5 | 0.3% | Oct 8, 2025 | A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying... |
| CVE-2025-60313 | MEDIUM | 6.1 | 0.3% | Oct 8, 2025 | Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input fi... |
| CVE-2025-43771 | MEDIUM | 5.4 | 0.2% | Oct 8, 2025 | Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.... |
| CVE-2025-43724 | MEDIUM | 4.4 | 0.1% | Oct 8, 2025 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerab... |
| CVE-2025-61183 | MEDIUM | 6.1 | 0.3% | Oct 8, 2025 | Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the stor... |
| CVE-2025-60833 | MEDIUM | 6.5 | 0.3% | Oct 8, 2025 | An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to e... |
| CVE-2025-60830 | MEDIUM | 6.5 | 0.3% | Oct 8, 2025 | redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key. |
| CVE-2025-60828 | MEDIUM | 6.5 | 0.3% | Oct 8, 2025 | WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine in... |
| CVE-2025-60314 | MEDIUM | 5.4 | 0.2% | Oct 8, 2025 | Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input... |
| CVE-2025-43830 | MEDIUM | 6.1 | 0.2% | Oct 8, 2025 | Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023... |
| CVE-2025-43829 | MEDIUM | 5.4 | 0.2% | Oct 8, 2025 | Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through ... |
| CVE-2025-60299 | MEDIUM | 5.4 | 0.2% | Oct 8, 2025 | Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addComme... |
| CVE-2025-60298 | MEDIUM | 5.4 | 0.2% | Oct 8, 2025 | Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updat... |
| CVE-2025-43821 | MEDIUM | 5.4 | 0.2% | Oct 8, 2025 | Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through... |
| CVE-2025-10649 | MEDIUM | 6.5 | 0.3% | Oct 8, 2025 | The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and inc... |
| CVE-2025-11445 | MEDIUM | 6.3 | 0.3% | Oct 8, 2025 | A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webv... |
| CVE-2025-11443 | MEDIUM | 5.9 | 0.5% | Oct 8, 2025 | A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/passwor... |
| CVE-2025-11442 | MEDIUM | 4.3 | 0.3% | Oct 8, 2025 | A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3. The impacted element is an unknown function of the c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now