2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58114 | MEDIUM | 4.8 | 0.2% | Sep 19, 2025 | Improper Input Validation vulnerability in Hallo Welt! GmbH BlueSpice (Extension:CognitiveProcessDesigner) allows Cross-... |
| CVE-2025-57880 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) all... |
| CVE-2025-48007 | MEDIUM | 6.4 | 0.2% | Sep 19, 2025 | Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows ... |
| CVE-2025-46703 | MEDIUM | 6.4 | 0.2% | Sep 19, 2025 | Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-... |
| CVE-2025-10715 | MEDIUM | 5.3 | 0.1% | Sep 19, 2025 | A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an ... |
| CVE-2025-10711 | MEDIUM | 4.3 | 0.3% | Sep 19, 2025 | A vulnerability has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This vulnerability affects unknown co... |
| CVE-2025-10710 | MEDIUM | 4.3 | 0.3% | Sep 19, 2025 | A flaw has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This affects an unknown part of the file /inde... |
| CVE-2025-8531 | MEDIUM | 6.8 | 1.0% | Sep 19, 2025 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03... |
| CVE-2025-10719 | MEDIUM | 5.3 | 0.3% | Sep 19, 2025 | Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers wit... |
| CVE-2025-10630 | MEDIUM | 4.3 | 0.3% | Sep 19, 2025 | Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to ... |
| CVE-2025-7702 | MEDIUM | 4.7 | 0.2% | Sep 19, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry ... |
| CVE-2025-7403 | MEDIUM | 6.5 | 0.2% | Sep 19, 2025 | Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes a... |
| CVE-2025-10456 | MEDIUM | 6.5 | 0.2% | Sep 19, 2025 | A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specif... |
| CVE-2025-10146 | MEDIUM | 6.1 | 0.2% | Sep 19, 2025 | The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter i... |
| CVE-2025-8487 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capabi... |
| CVE-2025-59715 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | SMSEagle before 6.11 allows reflected XSS via a username or contact phone number. |
| CVE-2025-59714 | MEDIUM | 4.9 | 0.2% | Sep 19, 2025 | In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs. |
| CVE-2025-59712 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | Snipe-IT before 8.1.18 allows XSS. |
| CVE-2025-30755 | MEDIUM | 6.1 | 0.2% | Sep 19, 2025 | OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens t... |
| CVE-2025-47906 | MEDIUM | 6.5 | 0.5% | Sep 18, 2025 | If the PATH environment variable contains paths which are executables (rather than just directories), passing certain st... |
| CVE-2025-26503 | MEDIUM | 6.7 | 0.1% | Sep 18, 2025 | A crafted system call argument can cause memory corruption. |
| CVE-2025-36146 | MEDIUM | 4.3 | 0.2% | Sep 18, 2025 | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version informat... |
| CVE-2025-36139 | MEDIUM | 4.8 | 0.2% | Sep 18, 2025 | IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged us... |
| CVE-2025-10676 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /b... |
| CVE-2025-10675 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now