2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61861 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially ... |
| CVE-2025-61860 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening sp... |
| CVE-2025-61859 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Open... |
| CVE-2025-61858 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening speci... |
| CVE-2025-61857 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlie... |
| CVE-2025-61856 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earl... |
| CVE-2025-52635 | CRITICAL | 9.8 | 0.2% | Oct 10, 2025 | A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION:... |
| CVE-2025-52625 | HIGH | 7.5 | 0.2% | Oct 10, 2025 | A vulnerability Cacheable SSL Page Found vulnerability has been identified in HCL AION. Cached data may expose cre... |
| CVE-2025-52624 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-... |
| CVE-2025-11190 | MEDIUM | 5.4 | 0.3% | Oct 10, 2025 | The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redire... |
| CVE-2025-11189 | HIGH | 7.3 | 0.4% | Oct 10, 2025 | The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, ... |
| CVE-2025-11188 | HIGH | 7.3 | 0.3% | Oct 10, 2025 | The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued... |
| CVE-2025-52650 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0 |
| CVE-2025-52634 | HIGH | 7.5 | 0.2% | Oct 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0. |
| CVE-2025-52632 | HIGH | 7.5 | 0.1% | Oct 10, 2025 | A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0. |
| CVE-2025-52630 | HIGH | 7.5 | 0.2% | Oct 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0. |
| CVE-2025-41089 | MEDIUM | 4.8 | 0.3% | Oct 10, 2025 | Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user in... |
| CVE-2025-41088 | MEDIUM | 5.1 | 0.3% | Oct 10, 2025 | Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. T... |
| CVE-2025-37727 | MEDIUM | 5.7 | 0.2% | Oct 10, 2025 | Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preco... |
| CVE-2025-30001 | HIGH | 7.3 | 0.5% | Oct 10, 2025 | Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from... |
| CVE-2025-25018 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS) |
| CVE-2025-25017 | MEDIUM | 6.1 | 0.3% | Oct 10, 2025 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS) |
| CVE-2025-52655 | LOW | 3.1 | 0.2% | Oct 10, 2025 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-part... |
| CVE-2025-40640 | MEDIUM | 5.4 | 0.2% | Oct 10, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du... |
| CVE-2025-62292 | MEDIUM | 4.3 | 0.2% | Oct 10, 2025 | In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now