2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61998 | MEDIUM | 4.8 | 0.2% | Oct 8, 2025 | OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within t... |
| CVE-2025-61997 | MEDIUM | 4.8 | 0.2% | Oct 8, 2025 | OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual... |
| CVE-2025-61996 | MEDIUM | 4.8 | 0.2% | Oct 8, 2025 | OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual... |
| CVE-2025-11417 | HIGH | 8.8 | 0.3% | Oct 8, 2025 | A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unk... |
| CVE-2025-6046 | — | — | — | Oct 7, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-43822 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP... |
| CVE-2025-11416 | CRITICAL | 9.8 | 0.4% | Oct 7, 2025 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of ... |
| CVE-2025-11415 | CRITICAL | 9.8 | 0.4% | Oct 7, 2025 | A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknow... |
| CVE-2025-11414 | MEDIUM | 5.5 | 0.2% | Oct 7, 2025 | A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry ... |
| CVE-2025-10904 | — | — | — | Oct 7, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-43823 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111,... |
| CVE-2025-11413 | MEDIUM | 5.5 | 0.2% | Oct 7, 2025 | A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elf... |
| CVE-2025-11412 | MEDIUM | 5.5 | 0.2% | Oct 7, 2025 | A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd... |
| CVE-2025-11410 | HIGH | 8.8 | 0.3% | Oct 7, 2025 | A flaw has been found in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the... |
| CVE-2025-62187 | LOW | 3.3 | 0.2% | Oct 7, 2025 | In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations o... |
| CVE-2025-62186 | HIGH | 7.8 | 0.1% | Oct 7, 2025 | Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio b... |
| CVE-2025-62185 | HIGH | 7.8 | 0.1% | Oct 7, 2025 | In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, a... |
| CVE-2025-34252 | — | — | — | Oct 7, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This vulnerability has been ... |
| CVE-2025-11409 | HIGH | 8.8 | 0.3% | Oct 7, 2025 | A vulnerability was detected in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unkno... |
| CVE-2025-11408 | CRITICAL | 9.8 | 0.8% | Oct 7, 2025 | A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element is an unknown functio... |
| CVE-2025-6242 | HIGH | 7.1 | 0.2% | Oct 7, 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimod... |
| CVE-2025-61910 | HIGH | 7.5 | 0.3% | Oct 7, 2025 | The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A BP... |
| CVE-2025-44824 | MEDIUM | 6.5 | 2.7% | Oct 7, 2025 | Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch ser... |
| CVE-2025-44823 | HIGH | 8.8 | 15.6% | Oct 7, 2025 | Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi... |
| CVE-2025-43910 | MEDIUM | 4.4 | 0.1% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now