2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53858 | MEDIUM | 5.4 | 0.2% | Oct 16, 2025 | ChatLuck contains a cross-site scripting vulnerability in Chat Rooms. If exploited, an arbitrary script may be executed ... |
| CVE-2025-41410 | MEDIUM | 5.4 | 0.3% | Oct 16, 2025 | Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Sl... |
| CVE-2025-10545 | MEDIUM | 4.3 | 0.3% | Oct 16, 2025 | Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding c... |
| CVE-2025-0277 | MEDIUM | 6.1 | 0.3% | Oct 16, 2025 | HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP)... |
| CVE-2025-0276 | MEDIUM | 6.1 | 0.3% | Oct 16, 2025 | HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Conte... |
| CVE-2025-55091 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou... |
| CVE-2025-41443 | MEDIUM | 4.3 | 0.3% | Oct 16, 2025 | Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessin... |
| CVE-2025-41021 | MEDIUM | 5.4 | 0.3% | Oct 16, 2025 | Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validati... |
| CVE-2025-41020 | HIGH | 7.5 | 0.3% | Oct 16, 2025 | Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker t... |
| CVE-2025-41019 | CRITICAL | 9.3 | 0.3% | Oct 16, 2025 | SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete... |
| CVE-2025-41018 | CRITICAL | 9.8 | 0.4% | Oct 16, 2025 | SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete d... |
| CVE-2025-62585 | HIGH | 7.5 | 0.3% | Oct 16, 2025 | Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dua... |
| CVE-2025-62584 | HIGH | 7.5 | 0.2% | Oct 16, 2025 | Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment. |
| CVE-2025-62583 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment. |
| CVE-2025-55090 | MEDIUM | 6.5 | 0.3% | Oct 16, 2025 | In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou... |
| CVE-2025-55089 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in t... |
| CVE-2025-55084 | MEDIUM | 5.3 | 0.3% | Oct 16, 2025 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_... |
| CVE-2025-10850 | CRITICAL | 9.8 | 0.6% | Oct 16, 2025 | The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.... |
| CVE-2025-10849 | MEDIUM | 5.3 | 0.3% | Oct 16, 2025 | The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2025-10742 | CRITICAL | 9.8 | 0.5% | Oct 16, 2025 | The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin... |
| CVE-2025-10706 | HIGH | 8.8 | 0.6% | Oct 16, 2025 | The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability che... |
| CVE-2025-58778 | HIGH | 8.6 | 0.5% | Oct 16, 2025 | Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the... |
| CVE-2025-0275 | MEDIUM | 4.3 | 0.2% | Oct 16, 2025 | HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset ... |
| CVE-2025-11814 | MEDIUM | 6.4 | 0.3% | Oct 16, 2025 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to... |
| CVE-2025-0274 | MEDIUM | 4.3 | 0.2% | Oct 16, 2025 | HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users ca... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now