2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54291 | MEDIUM | 5.3 | 0.4% | Oct 2, 2025 | Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remo... |
| CVE-2025-54290 | MEDIUM | 5.3 | 0.3% | Oct 2, 2025 | Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to d... |
| CVE-2025-54288 | MEDIUM | 6.8 | 0.3% | Oct 2, 2025 | Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attack... |
| CVE-2025-54287 | MEDIUM | 6.5 | 0.3% | Oct 2, 2025 | Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance co... |
| CVE-2025-40646 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information a... |
| CVE-2025-61583 | MEDIUM | 6.1 | 0.2% | Oct 1, 2025 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability h... |
| CVE-2025-61587 | MEDIUM | 6.1 | 0.4% | Oct 1, 2025 | Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter o... |
| CVE-2025-59337 | MEDIUM | 6.8 | 0.3% | Oct 1, 2025 | Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be... |
| CVE-2025-57389 | MEDIUM | 5.4 | 0.2% | Oct 1, 2025 | A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 all... |
| CVE-2025-61189 | MEDIUM | 6.3 | 0.2% | Oct 1, 2025 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFil... |
| CVE-2025-61188 | MEDIUM | 6.3 | 0.2% | Oct 1, 2025 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers... |
| CVE-2025-59149 | MEDIUM | 6.2 | 0.2% | Oct 1, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-57444 | MEDIUM | 6.1 | 0.2% | Oct 1, 2025 | An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Man... |
| CVE-2025-59682 | MEDIUM | 6.5 | 0.9% | Oct 1, 2025 | An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.e... |
| CVE-2025-58055 | MEDIUM | 4.3 | 0.2% | Oct 1, 2025 | Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endp... |
| CVE-2025-58054 | MEDIUM | 5.4 | 0.2% | Oct 1, 2025 | Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks throug... |
| CVE-2025-34182 | MEDIUM | 5.1 | 0.3% | Oct 1, 2025 | In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the paramet... |
| CVE-2025-20370 | MEDIUM | 4.9 | 0.5% | Oct 1, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.1... |
| CVE-2025-20369 | MEDIUM | 6.5 | 0.3% | Oct 1, 2025 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.... |
| CVE-2025-20368 | MEDIUM | 5.4 | 0.3% | Oct 1, 2025 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.... |
| CVE-2025-20367 | MEDIUM | 5.4 | 0.3% | Oct 1, 2025 | In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2... |
| CVE-2025-20366 | MEDIUM | 6.5 | 0.4% | Oct 1, 2025 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.... |
| CVE-2025-20361 | MEDIUM | 4.8 | 0.2% | Oct 1, 2025 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni... |
| CVE-2025-20357 | MEDIUM | 5.4 | 0.2% | Oct 1, 2025 | A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote ... |
| CVE-2025-20356 | MEDIUM | 5.4 | 0.2% | Oct 1, 2025 | A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now