2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59745 | HIGH | 7.5 | 0.2% | Oct 2, 2025 | Vulnerability in the cryptographic algorithm of AndSoft's e-TMS v25.03, which uses MD5 to encrypt passwords. MD5 is a cr... |
| CVE-2025-59744 | HIGH | 7.5 | 0.4% | Oct 2, 2025 | Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to access files only withi... |
| CVE-2025-59743 | CRITICAL | 9.8 | 0.3% | Oct 2, 2025 | SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u... |
| CVE-2025-59742 | CRITICAL | 9.8 | 0.3% | Oct 2, 2025 | SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, u... |
| CVE-2025-59741 | CRITICAL | 9.8 | 1.3% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-57443 | MEDIUM | 5.1 | 0.1% | Oct 2, 2025 | FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library... |
| CVE-2025-59740 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59739 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59738 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59737 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59736 | CRITICAL | 9.8 | 1.4% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-59735 | CRITICAL | 9.8 | 1.5% | Oct 2, 2025 | Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe... |
| CVE-2025-56381 | MEDIUM | 6.5 | 0.3% | Oct 2, 2025 | ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportv... |
| CVE-2025-56380 | MEDIUM | 6.5 | 0.3% | Oct 2, 2025 | Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the fra... |
| CVE-2025-56379 | MEDIUM | 5.4 | 0.4% | Oct 2, 2025 | A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execu... |
| CVE-2025-53881 | MEDIUM | 6.9 | 0.2% | Oct 2, 2025 | A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalat... |
| CVE-2025-41010 | MEDIUM | 5.1 | 0.3% | Oct 2, 2025 | Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) all... |
| CVE-2025-22862 | MEDIUM | 6.7 | 0.2% | Oct 2, 2025 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.... |
| CVE-2025-11240 | HIGH | 7.2 | 0.2% | Oct 2, 2025 | An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker... |
| CVE-2025-11239 | MEDIUM | 4.3 | 0.2% | Oct 2, 2025 | Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user'... |
| CVE-2025-0642 | MEDIUM | 6.3 | 0.2% | Oct 2, 2025 | Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Softwa... |
| CVE-2025-41064 | CRITICAL | 9.3 | 0.4% | Oct 2, 2025 | Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as... |
| CVE-2025-54293 | MEDIUM | 6.5 | 0.5% | Oct 2, 2025 | Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attacker... |
| CVE-2025-40992 | MEDIUM | 5.1 | 0.3% | Oct 2, 2025 | Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/soc... |
| CVE-2025-40991 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now