2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57109 | MEDIUM | 6.5 | 0.3% | Oct 30, 2025 | Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When pr... |
| CVE-2025-52180 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated atta... |
| CVE-2025-52179 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated at... |
| CVE-2025-36137 | HIGH | 7.2 | 0.3% | Oct 30, 2025 | IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 throu... |
| CVE-2025-64118 | MEDIUM | 6.1 | 0.1% | Oct 30, 2025 | node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uni... |
| CVE-2025-64116 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts... |
| CVE-2025-64115 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use... |
| CVE-2025-64112 | HIGH | 8 | 0.3% | Oct 30, 2025 | Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Ta... |
| CVE-2025-62266 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 20... |
| CVE-2025-56313 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3... |
| CVE-2025-64096 | HIGH | 8.8 | 0.5% | Oct 30, 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
| CVE-2025-63885 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to execute arbitrary web sc... |
| CVE-2025-62795 | HIGH | 7.1 | 0.3% | Oct 30, 2025 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts ... |
| CVE-2025-62726 | HIGH | 8.8 | 0.8% | Oct 30, 2025 | n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in th... |
| CVE-2025-61196 | HIGH | 8.8 | 0.5% | Oct 30, 2025 | An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input pa... |
| CVE-2025-61121 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., ... |
| CVE-2025-61120 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., con... |
| CVE-2025-61119 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access cont... |
| CVE-2025-61114 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | 2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., con... |
| CVE-2025-60950 | MEDIUM | 6.1 | 0.3% | Oct 30, 2025 | An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to ex... |
| CVE-2025-60319 | MEDIUM | 6.5 | 0.2% | Oct 30, 2025 | PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttac... |
| CVE-2025-12060 | HIGH | 8.9 | 0.6% | Oct 30, 2025 | The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path ... |
| CVE-2025-62712 | HIGH | 8.1 | 0.5% | Oct 30, 2025 | JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions... |
| CVE-2025-61118 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper acces... |
| CVE-2025-61117 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an impro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now