2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43824 | MEDIUM | 5.4 | 0.2% | Oct 6, 2025 | The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 ... |
| CVE-2025-59452 | MEDIUM | 5.8 | 0.4% | Oct 6, 2025 | The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an... |
| CVE-2025-59451 | LOW | 3.5 | 0.3% | Oct 6, 2025 | The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes. |
| CVE-2025-59450 | MEDIUM | 4.3 | 0.1% | Oct 6, 2025 | The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network a... |
| CVE-2025-59449 | MEDIUM | 4.9 | 0.3% | Oct 6, 2025 | The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-ac... |
| CVE-2025-59448 | MEDIUM | 4.7 | 0.2% | Oct 6, 2025 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet... |
| CVE-2025-59447 | LOW | 2.2 | 0.2% | Oct 6, 2025 | The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can lev... |
| CVE-2025-11346 | CRITICAL | 9.8 | 0.4% | Oct 6, 2025 | A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Bas... |
| CVE-2025-61985 | LOW | 3.6 | 0.1% | Oct 6, 2025 | ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a Prox... |
| CVE-2025-61984 | LOW | 3.6 | 0.2% | Oct 6, 2025 | ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources... |
| CVE-2025-11345 | CRITICAL | 9.8 | 0.3% | Oct 6, 2025 | A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component... |
| CVE-2025-11344 | CRITICAL | 9.8 | 0.5% | Oct 6, 2025 | A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality o... |
| CVE-2025-6985 | HIGH | 7.5 | 0.6% | Oct 6, 2025 | The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attac... |
| CVE-2025-57515 | CRITICAL | 9.8 | 0.5% | Oct 6, 2025 | A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to in... |
| CVE-2025-56382 | MEDIUM | 6.1 | 0.2% | Oct 6, 2025 | A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4... |
| CVE-2025-28129 | MEDIUM | 5.4 | 0.2% | Oct 6, 2025 | Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking. |
| CVE-2025-11343 | HIGH | 8.6 | 0.4% | Oct 6, 2025 | A security vulnerability has been detected in code-projects Student Crud Operation 3.3. Affected is an unknown function ... |
| CVE-2025-11342 | CRITICAL | 9.8 | 0.4% | Oct 6, 2025 | A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the ... |
| CVE-2025-61778 | CRITICAL | 9.3 | 0.4% | Oct 6, 2025 | Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 ... |
| CVE-2025-61777 | CRITICAL | 9.1 | 0.4% | Oct 6, 2025 | Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/b... |
| CVE-2025-61769 | MEDIUM | 6.1 | 0.3% | Oct 6, 2025 | Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including... |
| CVE-2025-61766 | MEDIUM | 6.5 | 0.3% | Oct 6, 2025 | Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recu... |
| CVE-2025-60969 | MEDIUM | 5.7 | 0.5% | Oct 6, 2025 | Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00... |
| CVE-2025-60967 | HIGH | 7.3 | 0.3% | Oct 6, 2025 | Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 V... |
| CVE-2025-60965 | CRITICAL | 9.1 | 1.4% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now