2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11192 | HIGH | 8.6 | 0.3% | Oct 7, 2025 | A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on... |
| CVE-2025-8291 | MEDIUM | 4.3 | 0.4% | Oct 7, 2025 | The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset val... |
| CVE-2025-43914 | HIGH | 7.8 | 0.1% | Oct 7, 2025 | Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS... |
| CVE-2025-43911 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43906 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-43890 | MEDIUM | 6.7 | 0.6% | Oct 7, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-3450 | CRITICAL | 10 | 0.3% | Oct 7, 2025 | An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before... |
| CVE-2025-36156 | HIGH | 7.8 | 0.1% | Oct 7, 2025 | IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused ... |
| CVE-2025-1826 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, ... |
| CVE-2025-11403 | CRITICAL | 9.8 | 0.3% | Oct 7, 2025 | A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this issue is some unknow... |
| CVE-2025-11402 | CRITICAL | 9.8 | 0.3% | Oct 7, 2025 | A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this vulnerability i... |
| CVE-2025-56243 | MEDIUM | 6.1 | 0.2% | Oct 7, 2025 | A Cross-Site Scripting (XSS) vulnerability was found in the register.php page of PuneethReddyHC Event Management System ... |
| CVE-2025-52021 | CRITICAL | 9.8 | 0.3% | Oct 7, 2025 | A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0.... |
| CVE-2025-11401 | CRITICAL | 9.8 | 0.3% | Oct 7, 2025 | A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the fi... |
| CVE-2025-60312 | MEDIUM | 6.1 | 0.3% | Oct 7, 2025 | Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" fie... |
| CVE-2025-11400 | CRITICAL | 9.8 | 0.3% | Oct 7, 2025 | A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function o... |
| CVE-2025-11399 | CRITICAL | 9.8 | 0.3% | Oct 7, 2025 | A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unkn... |
| CVE-2025-61772 | HIGH | 7.5 | 0.8% | Oct 7, 2025 | Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` c... |
| CVE-2025-61771 | HIGH | 7.5 | 0.5% | Oct 7, 2025 | Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` ... |
| CVE-2025-61770 | HIGH | 7.5 | 0.8% | Oct 7, 2025 | Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` b... |
| CVE-2025-11398 | HIGH | 8.8 | 0.4% | Oct 7, 2025 | A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unkno... |
| CVE-2025-59425 | HIGH | 7.5 | 0.5% | Oct 7, 2025 | vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support ... |
| CVE-2025-57564 | HIGH | 8.2 | 0.4% | Oct 7, 2025 | CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via... |
| CVE-2025-54406 | HIGH | 8.8 | 4.2% | Oct 7, 2025 | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A... |
| CVE-2025-54405 | HIGH | 8.8 | 4.2% | Oct 7, 2025 | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now