2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12308 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unk... |
| CVE-2025-12307 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was identified in code-projects Nero Social Networking Site 1.0. Affected by this vulnerability is an un... |
| CVE-2025-12306 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was determined in code-projects Nero Social Networking Site 1.0. Affected is an unknown function of the ... |
| CVE-2025-12305 | CRITICAL | 9.8 | 0.5% | Oct 27, 2025 | A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/ja... |
| CVE-2025-12304 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affe... |
| CVE-2025-61795 | MEDIUM | 5.3 | 1.1% | Oct 27, 2025 | Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits)... |
| CVE-2025-61385 | CRITICAL | 9.6 | 0.3% | Oct 27, 2025 | SQL injection vulnerability in tlocke pg8000 1.31.4 allows remote attackers to execute arbitrary SQL commands via a spec... |
| CVE-2025-60983 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Reflected Cross Site Scripting vulnerability in Rubikon Banking Solution 4.0.3 in the "Search For Customers Information"... |
| CVE-2025-60982 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object r... |
| CVE-2025-55754 | CRITICAL | 9.6 | 9.9% | Oct 27, 2025 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANS... |
| CVE-2025-55752 | HIGH | 7.5 | 66.5% | Oct 27, 2025 | Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the r... |
| CVE-2025-54965 | MEDIUM | 6.1 | 0.2% | Oct 27, 2025 | An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize... |
| CVE-2025-12364 | CRITICAL | 9.8 | 0.3% | Oct 27, 2025 | Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12363 | HIGH | 7.5 | 0.3% | Oct 27, 2025 | Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12303 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of ... |
| CVE-2025-12302 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown functi... |
| CVE-2025-12301 | CRITICAL | 9.8 | 0.5% | Oct 27, 2025 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown func... |
| CVE-2025-12300 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown process... |
| CVE-2025-54970 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests... |
| CVE-2025-54969 | MEDIUM | 6.1 | 0.1% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protec... |
| CVE-2025-54968 | HIGH | 8.8 | 0.4% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In s... |
| CVE-2025-54967 | MEDIUM | 6.5 | 0.3% | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An att... |
| CVE-2025-27225 | HIGH | 7.5 | 17.6% | Oct 27, 2025 | TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unau... |
| CVE-2025-27224 | CRITICAL | 9.8 | 0.8% | Oct 27, 2025 | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the applic... |
| CVE-2025-27223 | HIGH | 7.5 | 2.1% | Oct 27, 2025 | TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now