2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71426 | HIGH | 7.1 | — | Sep 27, 2026 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not... |
| CVE-2025-71425 | HIGH | 7.3 | — | Sep 27, 2026 | Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contr... |
| CVE-2025-71423 | HIGH | 7.3 | — | Sep 27, 2026 | Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initialize... |
| CVE-2025-51457 | HIGH | 8.8 | — | Sep 25, 2026 | D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at ... |
| CVE-2025-1281 | HIGH | 8.8 | 0.6% | Sep 22, 2026 | The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid... |
| CVE-2025-71421 | HIGH | 7.2 | 0.4% | Sep 21, 2026 | UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint tha... |
| CVE-2025-61682 | HIGH | 8.6 | 0.3% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2025-14754 | HIGH | 8.8 | 0.7% | Sep 18, 2026 | IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on... |
| CVE-2025-14753 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send... |
| CVE-2025-15697 | HIGH | 7.1 | — | Sep 17, 2026 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of sev... |
| CVE-2025-59607 | HIGH | 7.8 | 0.1% | Sep 17, 2026 | Memory Corruption when copying large input data exceeds normal allocation limits. |
| CVE-2025-56565 | HIGH | 7.6 | 0.2% | Sep 16, 2026 | DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in... |
| CVE-2025-14871 | HIGH | 7.5 | — | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and... |
| CVE-2025-66974 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attacke... |
| CVE-2025-15679 | HIGH | 7.3 | 0.1% | Sep 11, 2026 | Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a pa... |
| CVE-2025-57231 | HIGH | 7.5 | 1.3% | Sep 10, 2026 | Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local file... |
| CVE-2025-9049 | HIGH | 8.8 | 0.2% | Sep 5, 2026 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a mi... |
| CVE-2025-12737 | HIGH | 8.4 | 0.2% | Sep 3, 2026 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This ov... |
| CVE-2025-15485 | HIGH | 8.2 | 0.2% | Sep 2, 2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowin... |
| CVE-2025-46418 | HIGH | 7.6 | 0.7% | Sep 2, 2026 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. |
| CVE-2025-12768 | HIGH | 8.6 | — | Sep 1, 2026 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could e... |
| CVE-2025-30156 | HIGH | 8.9 | 0.1% | Aug 28, 2026 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2... |
| CVE-2025-61480 | HIGH | 7.5 | 0.1% | Aug 26, 2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ... |
| CVE-2025-61479 | HIGH | 7.5 | 0.2% | Aug 26, 2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ... |
| CVE-2025-61478 | HIGH | 7.5 | 0.3% | Aug 26, 2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now