2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60280 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code ... |
| CVE-2025-22166 | HIGH | 7.5 | 0.5% | Oct 21, 2025 | This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. Thi... |
| CVE-2025-12024 | — | — | — | Oct 21, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-60934 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Perfor... |
| CVE-2025-60933 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Perf... |
| CVE-2025-60932 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Per... |
| CVE-2025-60344 | HIGH | 8.6 | 10.3% | Oct 21, 2025 | A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker... |
| CVE-2025-59438 | MEDIUM | 5.3 | 0.2% | Oct 21, 2025 | Mbed TLS through 3.6.4 has an Observable Timing Discrepancy. |
| CVE-2025-57521 | MEDIUM | 6.1 | 0.1% | Oct 21, 2025 | Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application... |
| CVE-2025-56450 | MEDIUM | 6.5 | 0.3% | Oct 21, 2025 | Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter ... |
| CVE-2025-9339 | HIGH | 7.1 | 0.3% | Oct 21, 2025 | SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in u... |
| CVE-2025-11625 | CRITICAL | 9.8 | 0.4% | Oct 21, 2025 | Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypa... |
| CVE-2025-11624 | CRITICAL | 9.8 | 0.3% | Oct 21, 2025 | Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger... |
| CVE-2025-11151 | HIGH | 8.2 | 0.3% | Oct 21, 2025 | Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized ... |
| CVE-2025-6239 | MEDIUM | 6.5 | 0.9% | Oct 21, 2025 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Di... |
| CVE-2025-10020 | HIGH | 8.8 | 4.7% | Oct 21, 2025 | Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability... |
| CVE-2025-9428 | HIGH | 8.8 | 25.4% | Oct 21, 2025 | Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key u... |
| CVE-2025-10641 | HIGH | 7.1 | 0.3% | Oct 21, 2025 | All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This a... |
| CVE-2025-10640 | CRITICAL | 9.8 | 0.9% | Oct 21, 2025 | An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side aut... |
| CVE-2025-10639 | HIGH | 8.8 | 0.9% | Oct 21, 2025 | The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TC... |
| CVE-2025-7473 | MEDIUM | 5.3 | 0.3% | Oct 21, 2025 | Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. |
| CVE-2025-5496 | LOW | 3.3 | 0.2% | Oct 21, 2025 | ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected b... |
| CVE-2025-10612 | MEDIUM | 6.1 | 0.2% | Oct 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Info... |
| CVE-2025-26392 | MEDIUM | 4.6 | 0.2% | Oct 21, 2025 | SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using... |
| CVE-2025-12004 | CRITICAL | 10 | 0.3% | Oct 21, 2025 | Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Ext... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now