2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63441 | HIGH | 7.3 | 0.2% | Nov 3, 2025 | Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u... |
| CVE-2025-50363 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name... |
| CVE-2025-12463 | CRITICAL | 9.8 | 0.5% | Nov 3, 2025 | An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` paramet... |
| CVE-2025-11953 | CRITICAL | 9.8 | 61.9% | Nov 3, 2025 | The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default... |
| CVE-2025-10280 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels includin... |
| CVE-2025-63453 | CRITICAL | 9.8 | 0.4% | Nov 3, 2025 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php. |
| CVE-2025-63452 | CRITICAL | 9.4 | 0.4% | Nov 3, 2025 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php. |
| CVE-2025-63451 | CRITICAL | 9.8 | 0.4% | Nov 3, 2025 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php. |
| CVE-2025-63450 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php. |
| CVE-2025-63449 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php. |
| CVE-2025-63448 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1. |
| CVE-2025-63447 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php. |
| CVE-2025-63446 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php. |
| CVE-2025-60785 | HIGH | 8.8 | 0.6% | Nov 3, 2025 | A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attac... |
| CVE-2025-60503 | HIGH | 8.7 | 0.3% | Nov 3, 2025 | A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 whe... |
| CVE-2025-36093 | HIGH | 7.4 | 0.2% | Nov 3, 2025 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content ... |
| CVE-2025-36092 | MEDIUM | 6.5 | 0.4% | Nov 3, 2025 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of ... |
| CVE-2025-36091 | MEDIUM | 4.3 | 0.3% | Nov 3, 2025 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards t... |
| CVE-2025-11761 | HIGH | 7.8 | 0.2% | Nov 3, 2025 | A potential security vulnerability has been identified in the HP Client Management Script Library software, which might ... |
| CVE-2025-8900 | CRITICAL | 9.8 | 0.3% | Nov 3, 2025 | The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. Thi... |
| CVE-2025-63443 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter. |
| CVE-2025-63442 | MEDIUM | 4.6 | 0.2% | Nov 3, 2025 | Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. T... |
| CVE-2025-60892 | MEDIUM | 6.8 | 0.1% | Nov 3, 2025 | An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-... |
| CVE-2025-45663 | MEDIUM | 6.5 | 0.3% | Nov 3, 2025 | An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure. |
| CVE-2025-29699 | MEDIUM | 6.5 | 0.3% | Nov 3, 2025 | NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now