2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36904 | CRITICAL | 9.8 | 0.2% | Sep 4, 2025 | WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384. |
| CVE-2025-36897 | CRITICAL | 9.8 | 0.3% | Sep 4, 2025 | In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This coul... |
| CVE-2025-36896 | CRITICAL | 9.8 | 0.2% | Sep 4, 2025 | WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106. |
| CVE-2025-36890 | CRITICAL | 9.8 | 0.2% | Sep 4, 2025 | Elevation of Privilege |
| CVE-2025-9928 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown fu... |
| CVE-2025-9927 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown functio... |
| CVE-2025-55747 | CRITICAL | 9.1 | 1.6% | Sep 3, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.... |
| CVE-2025-9926 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the fil... |
| CVE-2025-9925 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability was found in projectworlds Travel Management System 1.0. This issue affects some unknown processing of t... |
| CVE-2025-53690 | CRITICAL | 9 | 26.3% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a... |
| CVE-2025-9924 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of... |
| CVE-2025-56752 | CRITICAL | 9.4 | 0.5% | Sep 3, 2025 | A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass auth... |
| CVE-2025-9919 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of... |
| CVE-2025-57148 | CRITICAL | 9.1 | 0.4% | Sep 3, 2025 | phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the la... |
| CVE-2025-57052 | CRITICAL | 9.8 | 0.7% | Sep 3, 2025 | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c... |
| CVE-2025-53693 | CRITICAL | 9.8 | 13.8% | Sep 3, 2025 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Ex... |
| CVE-2025-1740 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas... |
| CVE-2025-58210 | CRITICAL | 9.8 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in ThemeMove Makeaholic makeaholic allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-9847 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of t... |
| CVE-2025-9840 | CRITICAL | 9.8 | 0.3% | Sep 2, 2025 | A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function... |
| CVE-2025-9839 | CRITICAL | 9.8 | 0.4% | Sep 2, 2025 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a... |
| CVE-2025-9838 | CRITICAL | 9.8 | 0.4% | Sep 2, 2025 | A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown functio... |
| CVE-2025-26416 | CRITICAL | 9.8 | 0.4% | Sep 2, 2025 | In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. ... |
| CVE-2025-22435 | CRITICAL | 9.8 | 0.2% | Sep 2, 2025 | In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired d... |
| CVE-2025-22429 | CRITICAL | 9.8 | 0.2% | Sep 2, 2025 | In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could le... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now