2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61188 | MEDIUM | 6.3 | 0.2% | Oct 1, 2025 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers... |
| CVE-2025-59149 | MEDIUM | 6.2 | 0.2% | Oct 1, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-57444 | MEDIUM | 6.1 | 0.2% | Oct 1, 2025 | An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Man... |
| CVE-2025-59682 | MEDIUM | 6.5 | 0.9% | Oct 1, 2025 | An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.e... |
| CVE-2025-58055 | MEDIUM | 4.3 | 0.2% | Oct 1, 2025 | Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endp... |
| CVE-2025-58054 | MEDIUM | 5.4 | 0.2% | Oct 1, 2025 | Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks throug... |
| CVE-2025-34182 | MEDIUM | 5.1 | 0.3% | Oct 1, 2025 | In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the paramet... |
| CVE-2025-20370 | MEDIUM | 4.9 | 0.5% | Oct 1, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.1... |
| CVE-2025-20369 | MEDIUM | 6.5 | 0.3% | Oct 1, 2025 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.... |
| CVE-2025-20368 | MEDIUM | 5.4 | 0.3% | Oct 1, 2025 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.... |
| CVE-2025-20367 | MEDIUM | 5.4 | 0.3% | Oct 1, 2025 | In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2... |
| CVE-2025-20366 | MEDIUM | 6.5 | 0.4% | Oct 1, 2025 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.... |
| CVE-2025-20361 | MEDIUM | 4.8 | 0.2% | Oct 1, 2025 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni... |
| CVE-2025-20357 | MEDIUM | 5.4 | 0.2% | Oct 1, 2025 | A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote ... |
| CVE-2025-20356 | MEDIUM | 5.4 | 0.2% | Oct 1, 2025 | A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote ... |
| CVE-2025-11233 | MEDIUM | 6.3 | 0.5% | Oct 1, 2025 | Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cygwin target (`x86_64-pc-cygwin`) didn't correctly handle ... |
| CVE-2025-56514 | MEDIUM | 5.4 | 0.3% | Oct 1, 2025 | Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malic... |
| CVE-2025-59687 | MEDIUM | 4.3 | 0.2% | Oct 1, 2025 | IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details,... |
| CVE-2025-59686 | MEDIUM | 6.5 | 0.2% | Oct 1, 2025 | Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id. |
| CVE-2025-59685 | MEDIUM | 5.3 | 0.3% | Oct 1, 2025 | Kazaar 1.25.12 allows a JWT with none in the alg field. |
| CVE-2025-57275 | MEDIUM | 5.5 | 0.3% | Oct 1, 2025 | Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPD... |
| CVE-2025-41421 | MEDIUM | 4.7 | 0.1% | Oct 1, 2025 | Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of T... |
| CVE-2025-40648 | MEDIUM | 4.8 | 0.3% | Oct 1, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper va... |
| CVE-2025-40647 | MEDIUM | 5.1 | 0.3% | Oct 1, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, consisting of a stored XSS due to a lack of proper va... |
| CVE-2025-39928 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: ensure data length is within supporte... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now