2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10914 | HIGH | 7.6 | 0.2% | Oct 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft... |
| CVE-2025-10727 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner S... |
| CVE-2025-62499 | MEDIUM | 4.8 | 0.2% | Oct 23, 2025 | Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted in... |
| CVE-2025-61865 | HIGH | 8.4 | 0.2% | Oct 23, 2025 | Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file path... |
| CVE-2025-54856 | MEDIUM | 4.8 | 0.2% | Oct 23, 2025 | Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored b... |
| CVE-2025-54806 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a... |
| CVE-2025-62820 | MEDIUM | 4.9 | 0.2% | Oct 23, 2025 | Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within t... |
| CVE-2025-62813 | — | — | — | Oct 23, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2025-48430 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Comm... |
| CVE-2025-48428 | MEDIUM | 6.7 | 0.1% | Oct 23, 2025 | Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated us... |
| CVE-2025-47699 | CRITICAL | 9.9 | 0.3% | Oct 23, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration... |
| CVE-2025-41402 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to e... |
| CVE-2025-35981 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privil... |
| CVE-2025-12104 | CRITICAL | 9.8 | 0.4% | Oct 23, 2025 | Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19.... |
| CVE-2025-62812 | — | — | — | Oct 23, 2025 | Rejected reason: Not used |
| CVE-2025-62811 | — | — | — | Oct 23, 2025 | Rejected reason: Not used |
| CVE-2025-62810 | — | — | — | Oct 23, 2025 | Rejected reason: Not used |
| CVE-2025-62809 | — | — | — | Oct 23, 2025 | Rejected reason: Not used |
| CVE-2025-62808 | — | — | — | Oct 23, 2025 | Rejected reason: Not used |
| CVE-2025-62807 | — | — | — | Oct 23, 2025 | Rejected reason: Not used |
| CVE-2025-62806 | — | — | — | Oct 23, 2025 | Rejected reason: Not used |
| CVE-2025-62805 | — | — | — | Oct 23, 2025 | Rejected reason: Not used |
| CVE-2025-62804 | — | — | — | Oct 23, 2025 | Rejected reason: Not used |
| CVE-2025-11575 | HIGH | 8.8 | 0.1% | Oct 23, 2025 | Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This... |
| CVE-2025-62710 | MEDIUM | 5.9 | 0.2% | Oct 22, 2025 | Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initial... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now