2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59754 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59753 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59752 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59751 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59750 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59749 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59748 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59747 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59746 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-57443 | MEDIUM | 5.1 | 0.1% | Oct 2, 2025 | FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library... |
| CVE-2025-56381 | MEDIUM | 6.5 | 0.3% | Oct 2, 2025 | ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportv... |
| CVE-2025-56380 | MEDIUM | 6.5 | 0.3% | Oct 2, 2025 | Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the fra... |
| CVE-2025-56379 | MEDIUM | 5.4 | 0.4% | Oct 2, 2025 | A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execu... |
| CVE-2025-53881 | MEDIUM | 6.9 | 0.2% | Oct 2, 2025 | A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalat... |
| CVE-2025-41010 | MEDIUM | 5.1 | 0.3% | Oct 2, 2025 | Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) all... |
| CVE-2025-22862 | MEDIUM | 6.7 | 0.2% | Oct 2, 2025 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.... |
| CVE-2025-11239 | MEDIUM | 4.3 | 0.2% | Oct 2, 2025 | Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user'... |
| CVE-2025-0642 | MEDIUM | 6.3 | 0.2% | Oct 2, 2025 | Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Softwa... |
| CVE-2025-54293 | MEDIUM | 6.5 | 0.5% | Oct 2, 2025 | Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attacker... |
| CVE-2025-40992 | MEDIUM | 5.1 | 0.3% | Oct 2, 2025 | Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/soc... |
| CVE-2025-40991 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ... |
| CVE-2025-40990 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ... |
| CVE-2025-40989 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ... |
| CVE-2025-54468 | MEDIUM | 4.7 | 0.3% | Oct 2, 2025 | A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an ex... |
| CVE-2025-54292 | MEDIUM | 4.6 | 0.3% | Oct 2, 2025 | Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attac... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now