2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62267 | MEDIUM | 6.1 | 0.2% | Oct 31, 2025 | Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.... |
| CVE-2025-12547 | HIGH | 8.1 | 0.8% | Oct 31, 2025 | A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of t... |
| CVE-2025-12546 | MEDIUM | 5.4 | 0.3% | Oct 31, 2025 | A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen... |
| CVE-2025-63459 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42... |
| CVE-2025-62264 | MEDIUM | 6.1 | 0.2% | Oct 31, 2025 | Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, an... |
| CVE-2025-6075 | MEDIUM | 5.5 | 0.1% | Oct 31, 2025 | If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env... |
| CVE-2025-63465 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42288... |
| CVE-2025-63464 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396... |
| CVE-2025-63463 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_42... |
| CVE-2025-63462 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4... |
| CVE-2025-63461 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldec... |
| CVE-2025-63460 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_42... |
| CVE-2025-59501 | MEDIUM | 4.8 | 3.1% | Oct 31, 2025 | Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing o... |
| CVE-2025-63469 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BA... |
| CVE-2025-63468 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_... |
| CVE-2025-63467 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42540... |
| CVE-2025-63466 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_4... |
| CVE-2025-29270 | CRITICAL | 10 | 0.3% | Oct 31, 2025 | Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows at... |
| CVE-2025-12554 | CRITICAL | 9.8 | 0.3% | Oct 31, 2025 | Missing Security Headers.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12553 | CRITICAL | 9.8 | 0.2% | Oct 31, 2025 | Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12552 | CRITICAL | 9.8 | 0.3% | Oct 31, 2025 | Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12509 | HIGH | 8.4 | 0.3% | Oct 31, 2025 | On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the B... |
| CVE-2025-12508 | HIGH | 8.4 | 0.2% | Oct 31, 2025 | When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to t... |
| CVE-2025-12507 | HIGH | 8.8 | 0.1% | Oct 31, 2025 | The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executa... |
| CVE-2025-12357 | MEDIUM | 6.3 | 0.2% | Oct 31, 2025 | By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker ca... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now