2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48097 | HIGH | 7.1 | 0.2% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shiva WSAnalytics ... |
| CVE-2025-48096 | MEDIUM | 6.5 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in FRESHFACE Custom CSS custom-css-editor allows Exploiting Incorrectly Configured A... |
| CVE-2025-48095 | MEDIUM | 5.9 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak... |
| CVE-2025-48093 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calvaweb Password ... |
| CVE-2025-48092 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jurajpuchky Fix Mu... |
| CVE-2025-48091 | HIGH | 8.5 | 0.4% | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComme... |
| CVE-2025-48082 | HIGH | 8.8 | 0.4% | Oct 22, 2025 | Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Esca... |
| CVE-2025-39534 | HIGH | 7.1 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Somonator Terms Di... |
| CVE-2025-32657 | HIGH | 7.5 | 0.6% | Oct 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32283 | HIGH | 8.8 | 0.6% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue af... |
| CVE-2025-31634 | HIGH | 8.8 | 0.6% | Oct 22, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue a... |
| CVE-2025-30944 | HIGH | 7.5 | 0.4% | Oct 22, 2025 | Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality ... |
| CVE-2025-11966 | MEDIUM | 6.4 | 0.3% | Oct 22, 2025 | In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory n... |
| CVE-2025-11965 | HIGH | 7.5 | 0.5% | Oct 22, 2025 | In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to h... |
| CVE-2025-8848 | MEDIUM | 5.4 | 0.4% | Oct 22, 2025 | A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a ... |
| CVE-2025-61035 | HIGH | 7.7 | 0.1% | Oct 22, 2025 | The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file... |
| CVE-2025-56447 | CRITICAL | 9.8 | 0.3% | Oct 22, 2025 | TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure. |
| CVE-2025-11844 | MEDIUM | 5.4 | 0.3% | Oct 22, 2025 | Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function loca... |
| CVE-2025-11750 | MEDIUM | 5.3 | 0.7% | Oct 22, 2025 | In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning d... |
| CVE-2025-11411 | MEDIUM | 5.7 | 0.3% | Oct 22, 2025 | NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RR... |
| CVE-2025-11086 | HIGH | 8.1 | 0.4% | Oct 22, 2025 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e... |
| CVE-2025-6833 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Inse... |
| CVE-2025-11915 | MEDIUM | 6.9 | 0.3% | Oct 22, 2025 | Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in f... |
| CVE-2025-41110 | HIGH | 8.8 | 0.2% | Oct 22, 2025 | Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an ... |
| CVE-2025-41109 | MEDIUM | 4.6 | 0.6% | Oct 22, 2025 | Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. T... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now