2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11584 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown functio... |
| CVE-2025-62245 | MEDIUM | 4.3 | 0.2% | Oct 10, 2025 | Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 thr... |
| CVE-2025-62158 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system d... |
| CVE-2025-61930 | HIGH | 8.8 | 0.2% | Oct 10, 2025 | Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Requ... |
| CVE-2025-61929 | CRITICAL | 9.6 | 0.4% | Oct 10, 2025 | Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol ca... |
| CVE-2025-61927 | HIGH | 7.2 | 0.6% | Oct 10, 2025 | Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower ... |
| CVE-2025-61925 | MEDIUM | 6.5 | 0.4% | Oct 10, 2025 | Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `... |
| CVE-2025-61921 | HIGH | 7.5 | 0.4% | Oct 10, 2025 | Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a deni... |
| CVE-2025-61920 | HIGH | 7.5 | 0.6% | Oct 10, 2025 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implem... |
| CVE-2025-61919 | HIGH | 7.5 | 0.6% | Oct 10, 2025 | Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the... |
| CVE-2025-55903 | HIGH | 8.3 | 0.3% | Oct 10, 2025 | A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To... |
| CVE-2025-11583 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjo... |
| CVE-2025-11582 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing o... |
| CVE-2025-61505 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-co... |
| CVE-2025-60880 | HIGH | 8.3 | 0.4% | Oct 10, 2025 | An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an a... |
| CVE-2025-11581 | HIGH | 7.5 | 0.4% | Oct 10, 2025 | A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file ... |
| CVE-2025-60838 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted... |
| CVE-2025-60268 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the sa... |
| CVE-2025-23309 | HIGH | 8.2 | 0.2% | Oct 10, 2025 | NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of ... |
| CVE-2025-23282 | HIGH | 7 | 0.2% | Oct 10, 2025 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to esca... |
| CVE-2025-23280 | HIGH | 7 | 0.2% | Oct 10, 2025 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful ex... |
| CVE-2025-11618 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer derefer... |
| CVE-2025-11617 | MEDIUM | 5.4 | 0.3% | Oct 10, 2025 | A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when rec... |
| CVE-2025-11616 | MEDIUM | 5.4 | 0.3% | Oct 10, 2025 | A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when r... |
| CVE-2025-11580 | MEDIUM | 5.5 | 1.0% | Oct 10, 2025 | A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This mani... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now