2025 CVE Vulnerabilities
45,152 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56380 | MEDIUM | 6.5 | 0.3% | Oct 2, 2025 | Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the fra... |
| CVE-2025-56379 | MEDIUM | 5.4 | 0.4% | Oct 2, 2025 | A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execu... |
| CVE-2025-53881 | MEDIUM | 6.9 | 0.2% | Oct 2, 2025 | A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalat... |
| CVE-2025-41010 | MEDIUM | 5.1 | 0.3% | Oct 2, 2025 | Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) all... |
| CVE-2025-22862 | MEDIUM | 6.7 | 0.2% | Oct 2, 2025 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.... |
| CVE-2025-11239 | MEDIUM | 4.3 | 0.2% | Oct 2, 2025 | Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user'... |
| CVE-2025-0642 | MEDIUM | 6.3 | 0.2% | Oct 2, 2025 | Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Softwa... |
| CVE-2025-54293 | MEDIUM | 6.5 | 0.5% | Oct 2, 2025 | Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attacker... |
| CVE-2025-40992 | MEDIUM | 5.1 | 0.3% | Oct 2, 2025 | Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/soc... |
| CVE-2025-40991 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ... |
| CVE-2025-40990 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ... |
| CVE-2025-40989 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ... |
| CVE-2025-54468 | MEDIUM | 4.7 | 0.3% | Oct 2, 2025 | A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an ex... |
| CVE-2025-54292 | MEDIUM | 4.6 | 0.3% | Oct 2, 2025 | Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attac... |
| CVE-2025-54291 | MEDIUM | 5.3 | 0.4% | Oct 2, 2025 | Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remo... |
| CVE-2025-54290 | MEDIUM | 5.3 | 0.3% | Oct 2, 2025 | Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to d... |
| CVE-2025-54288 | MEDIUM | 6.8 | 0.3% | Oct 2, 2025 | Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attack... |
| CVE-2025-54287 | MEDIUM | 6.5 | 0.3% | Oct 2, 2025 | Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance co... |
| CVE-2025-40646 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information a... |
| CVE-2025-61583 | MEDIUM | 6.1 | 0.2% | Oct 1, 2025 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability h... |
| CVE-2025-61587 | MEDIUM | 6.1 | 0.4% | Oct 1, 2025 | Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter o... |
| CVE-2025-59337 | MEDIUM | 6.8 | 0.3% | Oct 1, 2025 | Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be... |
| CVE-2025-57389 | MEDIUM | 5.4 | 0.2% | Oct 1, 2025 | A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 all... |
| CVE-2025-61189 | MEDIUM | 6.3 | 0.2% | Oct 1, 2025 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFil... |
| CVE-2025-61188 | MEDIUM | 6.3 | 0.2% | Oct 1, 2025 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now