2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62177 | HIGH | 8.8 | 0.5% | Oct 13, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL In... |
| CVE-2025-11623 | MEDIUM | 6.5 | 0.8% | Oct 13, 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar... |
| CVE-2025-9713 | HIGH | 8.8 | 14.5% | Oct 13, 2025 | Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve re... |
| CVE-2025-62364 | MEDIUM | 6.2 | 0.5% | Oct 13, 2025 | text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Loc... |
| CVE-2025-62252 | MEDIUM | 4.3 | 0.2% | Oct 13, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported v... |
| CVE-2025-62246 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsuppor... |
| CVE-2025-62176 | MEDIUM | 4.3 | 0.3% | Oct 13, 2025 | Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27... |
| CVE-2025-62175 | MEDIUM | 4.3 | 0.2% | Oct 13, 2025 | Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27... |
| CVE-2025-62174 | LOW | 3.5 | 0.2% | Oct 13, 2025 | Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.2... |
| CVE-2025-61688 | HIGH | 7.5 | 0.3% | Oct 13, 2025 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensit... |
| CVE-2025-59836 | HIGH | 7.5 | 0.5% | Oct 13, 2025 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer... |
| CVE-2025-11622 | HIGH | 7.8 | 0.7% | Oct 13, 2025 | Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to esc... |
| CVE-2025-62242 | MEDIUM | 4.3 | 0.3% | Oct 13, 2025 | Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111... |
| CVE-2025-62241 | MEDIUM | 4.3 | 0.2% | Oct 13, 2025 | Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5... |
| CVE-2025-58084 | MEDIUM | 6.5 | 0.3% | Oct 13, 2025 | Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing ... |
| CVE-2025-62243 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Lif... |
| CVE-2025-62170 | HIGH | 7.5 | 0.3% | Oct 13, 2025 | rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality... |
| CVE-2025-61775 | MEDIUM | 6.9 | 0.3% | Oct 13, 2025 | Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unex... |
| CVE-2025-7707 | HIGH | 7.8 | 0.2% | Oct 13, 2025 | The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which... |
| CVE-2025-62244 | MEDIUM | 4.3 | 0.3% | Oct 13, 2025 | Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Lif... |
| CVE-2025-11695 | HIGH | 7.5 | 0.2% | Oct 13, 2025 | When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects M... |
| CVE-2025-43991 | HIGH | 7.1 | 0.1% | Oct 13, 2025 | SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain... |
| CVE-2025-39965 | MEDIUM | 5.5 | 0.2% | Oct 13, 2025 | In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.... |
| CVE-2025-39964 | LOW | 3.3 | 0.2% | Oct 13, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_a... |
| CVE-2025-37729 | HIGH | 7.2 | 0.6% | Oct 13, 2025 | Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a ma... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now