2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63564 | CRITICAL | 9.8 | 0.5% | Sep 23, 2026 | SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code... |
| CVE-2025-12999 | CRITICAL | 9.1 | 0.4% | Sep 21, 2026 | UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwa... |
| CVE-2025-66455 | CRITICAL | 9.8 | 0.7% | Sep 18, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior... |
| CVE-2025-53837 | CRITICAL | 9.9 | 0.6% | Sep 18, 2026 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int... |
| CVE-2025-15399 | CRITICAL | 10 | 0.3% | Sep 18, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro... |
| CVE-2025-55787 | CRITICAL | 9.8 | 0.3% | Sep 17, 2026 | In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists. |
| CVE-2025-56563 | CRITICAL | 9.8 | 0.4% | Sep 16, 2026 | A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts ... |
| CVE-2025-59953 | CRITICAL | 9.8 | 0.8% | Sep 16, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior... |
| CVE-2025-43936 | CRITICAL | 9.1 | 0.5% | Sep 16, 2026 | Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthent... |
| CVE-2025-67066 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtyp... |
| CVE-2025-9314 | CRITICAL | 9.8 | 0.3% | Sep 2, 2026 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in th... |
| CVE-2025-51679 | CRITICAL | 9.1 | 0.4% | Aug 26, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected ... |
| CVE-2025-70293 | CRITICAL | 9.8 | 0.5% | Aug 26, 2026 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_b... |
| CVE-2025-70290 | CRITICAL | 9.8 | 0.5% | Aug 26, 2026 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support c... |
| CVE-2025-61165 | CRITICAL | 9.8 | 0.4% | Aug 26, 2026 | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac... |
| CVE-2025-61163 | CRITICAL | 9.8 | 0.3% | Aug 26, 2026 | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This... |
| CVE-2025-15689 | CRITICAL | 9.8 | — | Aug 20, 2026 | Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. |
| CVE-2025-15688 | CRITICAL | 9.3 | — | Aug 20, 2026 | Unauthenticated SQL Injection in Capella <= 2.5.5 versions. |
| CVE-2025-14600 | CRITICAL | 9.3 | — | Aug 19, 2026 | An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access.... |
| CVE-2025-59324 | CRITICAL | 9.1 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is ... |
| CVE-2025-59321 | CRITICAL | 9.8 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the syst... |
| CVE-2025-59326 | CRITICAL | 9.8 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file sys... |
| CVE-2025-41769 | CRITICAL | 9.8 | — | Aug 12, 2026 | The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. A... |
| CVE-2025-31114 | CRITICAL | 9.3 | — | Aug 11, 2026 | Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code ex... |
| CVE-2025-15681 | CRITICAL | 9.2 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now