2025 CVE Vulnerabilities
45,212 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54764 | MEDIUM | 6.2 | 0.2% | Oct 20, 2025 | Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i... |
| CVE-2025-12001 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B... |
| CVE-2025-11536 | MEDIUM | 5 | 0.2% | Oct 20, 2025 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver... |
| CVE-2025-62658 | HIGH | 7.5 | 0.2% | Oct 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foun... |
| CVE-2025-62657 | MEDIUM | 5.8 | 0.2% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62656 | MEDIUM | 5.8 | 0.2% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-61303 | CRITICAL | 9.8 | 0.4% | Oct 20, 2025 | Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability... |
| CVE-2025-61301 | HIGH | 7.5 | 0.4% | Oct 20, 2025 | Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows at... |
| CVE-2025-60783 | MEDIUM | 6.5 | 0.2% | Oct 20, 2025 | There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerabilit... |
| CVE-2025-60781 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_nam... |
| CVE-2025-8053 | CRITICAL | 9.1 | 0.2% | Oct 20, 2025 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-8052 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | SQL Injection vulnerability in opentext Flipper allows SQL Injection. The vulnerability could allow a low privilege us... |
| CVE-2025-8051 | MEDIUM | 6.5 | 0.4% | Oct 20, 2025 | Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal. The vulnerability could allow a user ... |
| CVE-2025-8049 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-8048 | MEDIUM | 6.5 | 0.3% | Oct 20, 2025 | External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could a... |
| CVE-2025-62697 | HIGH | 8.8 | 0.3% | Oct 20, 2025 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The ... |
| CVE-2025-62528 | MEDIUM | 5.4 | 0.2% | Oct 20, 2025 | Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ... |
| CVE-2025-62527 | HIGH | 7.1 | 0.2% | Oct 20, 2025 | Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ... |
| CVE-2025-62522 | MEDIUM | 6 | 1.0% | Oct 20, 2025 | Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5... |
| CVE-2025-61488 | HIGH | 7.6 | 0.3% | Oct 20, 2025 | An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary cod... |
| CVE-2025-5517 | MEDIUM | 6.8 | 0.3% | Oct 20, 2025 | Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC ... |
| CVE-2025-62700 | MEDIUM | 6.9 | 0.3% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62698 | MEDIUM | 6.9 | 0.3% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62693 | MEDIUM | 6.9 | 0.3% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62510 | HIGH | 8.1 | 0.3% | Oct 20, 2025 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now