2025 CVE Vulnerabilities
45,328 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40649 | MEDIUM | 5.1 | 0.3% | Oct 7, 2025 | Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infras... |
| CVE-2025-3718 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing valid... |
| CVE-2025-11390 | MEDIUM | 6.1 | 0.3% | Oct 7, 2025 | A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-11360 | MEDIUM | 5.3 | 0.3% | Oct 7, 2025 | A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the ... |
| CVE-2025-10645 | MEDIUM | 5.3 | 0.3% | Oct 7, 2025 | The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ... |
| CVE-2025-7400 | MEDIUM | 6.4 | 0.2% | Oct 7, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featur... |
| CVE-2025-61768 | MEDIUM | 5.1 | 0.3% | Oct 6, 2025 | KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Fo... |
| CVE-2025-43824 | MEDIUM | 5.4 | 0.2% | Oct 6, 2025 | The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 ... |
| CVE-2025-59452 | MEDIUM | 5.8 | 0.4% | Oct 6, 2025 | The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an... |
| CVE-2025-59450 | MEDIUM | 4.3 | 0.1% | Oct 6, 2025 | The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network a... |
| CVE-2025-59449 | MEDIUM | 4.9 | 0.3% | Oct 6, 2025 | The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-ac... |
| CVE-2025-59448 | MEDIUM | 4.7 | 0.2% | Oct 6, 2025 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet... |
| CVE-2025-56382 | MEDIUM | 6.1 | 0.2% | Oct 6, 2025 | A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4... |
| CVE-2025-28129 | MEDIUM | 5.4 | 0.2% | Oct 6, 2025 | Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking. |
| CVE-2025-61769 | MEDIUM | 6.1 | 0.3% | Oct 6, 2025 | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including... |
| CVE-2025-61766 | MEDIUM | 6.5 | 0.3% | Oct 6, 2025 | Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recu... |
| CVE-2025-60969 | MEDIUM | 5.7 | 0.5% | Oct 6, 2025 | Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00... |
| CVE-2025-60961 | MEDIUM | 6.1 | 0.2% | Oct 6, 2025 | Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 V... |
| CVE-2025-0038 | MEDIUM | 6.6 | 0.1% | Oct 6, 2025 | In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firm... |
| CVE-2025-61765 | MEDIUM | 6.4 | 0.5% | Oct 6, 2025 | python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerab... |
| CVE-2025-61224 | MEDIUM | 6.5 | 1.3% | Oct 6, 2025 | Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra... |
| CVE-2025-61198 | MEDIUM | 5.4 | 0.2% | Oct 6, 2025 | A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Opt... |
| CVE-2025-11337 | MEDIUM | 5.5 | 0.6% | Oct 6, 2025 | A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown... |
| CVE-2025-11336 | MEDIUM | 5.5 | 0.6% | Oct 6, 2025 | A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected ... |
| CVE-2025-11332 | MEDIUM | 6.1 | 0.3% | Oct 6, 2025 | A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now