2025 CVE Vulnerabilities
45,328 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36565 | MEDIUM | 6.7 | 0.2% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-11406 | MEDIUM | 4.3 | 0.2% | Oct 7, 2025 | A security flaw has been discovered in kaifangqian kaifangqian-base up to 7b3faecda13848b3ced6c17c7423b76c5b47b8ab. This... |
| CVE-2025-61776 | MEDIUM | 4.7 | 0.3% | Oct 7, 2025 | Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software ... |
| CVE-2025-45375 | MEDIUM | 4.4 | 0.1% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43934 | MEDIUM | 6 | 0.2% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43913 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43908 | MEDIUM | 6.7 | 0.4% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43907 | MEDIUM | 6.5 | 0.4% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43905 | MEDIUM | 6.5 | 0.3% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-3449 | MEDIUM | 4.2 | 0.2% | Oct 7, 2025 | A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions... |
| CVE-2025-3448 | MEDIUM | 6.1 | 0.2% | Oct 7, 2025 | Reflected cross-site scripting (XSS) vulnerabilities exist in System Diagnostics Manager (SDM) of B&R Automation Runtime... |
| CVE-2025-8291 | MEDIUM | 4.3 | 0.4% | Oct 7, 2025 | The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset val... |
| CVE-2025-43911 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43906 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43890 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-1826 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, ... |
| CVE-2025-56243 | MEDIUM | 6.1 | 0.2% | Oct 7, 2025 | A Cross-Site Scripting (XSS) vulnerability was found in the register.php page of PuneethReddyHC Event Management System ... |
| CVE-2025-60312 | MEDIUM | 6.1 | 0.3% | Oct 7, 2025 | Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" fie... |
| CVE-2025-53476 | MEDIUM | 5.3 | 0.3% | Oct 7, 2025 | A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5c... |
| CVE-2025-37728 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A ma... |
| CVE-2025-25009 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload. |
| CVE-2025-40888 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. ... |
| CVE-2025-40887 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter... |
| CVE-2025-40885 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input p... |
| CVE-2025-40676 | MEDIUM | 5.3 | 0.2% | Oct 7, 2025 | Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Rese... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now