2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61116 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arsh... |
| CVE-2025-61115 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed... |
| CVE-2025-61113 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API endpoints. By modifying requ... |
| CVE-2025-46363 | MEDIUM | 4.3 | 0.3% | Oct 30, 2025 | Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative P... |
| CVE-2025-36592 | MEDIUM | 5.4 | 0.2% | Oct 30, 2025 | Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutra... |
| CVE-2025-12517 | MEDIUM | 5.3 | 0.2% | Oct 30, 2025 | Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.... |
| CVE-2025-12516 | CRITICAL | 9.8 | 0.3% | Oct 30, 2025 | Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-12515 | CRITICAL | 9.8 | 0.3% | Oct 30, 2025 | Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . |
| CVE-2025-11998 | MEDIUM | 6.8 | 0.2% | Oct 30, 2025 | The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing ... |
| CVE-2025-5347 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the r... |
| CVE-2025-5343 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the ... |
| CVE-2025-5342 | MEDIUM | 6.5 | 1.0% | Oct 30, 2025 | Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module. |
| CVE-2025-50574 | MEDIUM | 6.1 | 0.3% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in blog-details.php in Hiruna Gallage's Glamour Salon Management System v1 allo... |
| CVE-2025-46423 | HIGH | 7.8 | 0.5% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-46422 | HIGH | 7.8 | 0.5% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-43942 | HIGH | 7.8 | 0.6% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-43027 | CRITICAL | 9.8 | 0.3% | Oct 30, 2025 | A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attac... |
| CVE-2025-50739 | CRITICAL | 9.8 | 0.6% | Oct 30, 2025 | iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization. |
| CVE-2025-50736 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause t... |
| CVE-2025-43941 | HIGH | 7.8 | 0.7% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-43940 | HIGH | 7.8 | 0.6% | Oct 30, 2025 | Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-43939 | HIGH | 7.8 | 0.6% | Oct 30, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-63608 | MEDIUM | 5.4 | 0.2% | Oct 30, 2025 | A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is loc... |
| CVE-2025-10348 | MEDIUM | 5.1 | 0.4% | Oct 30, 2025 | URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account... |
| CVE-2025-10317 | MEDIUM | 5.1 | 0.2% | Oct 30, 2025 | Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now