2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9599 | CRITICAL | 9.8 | 0.4% | Aug 29, 2025 | A weakness has been identified in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unk... |
| CVE-2025-9598 | CRITICAL | 9.8 | 0.4% | Aug 29, 2025 | A security flaw has been discovered in itsourcecode Apartment Management System 1.0. Affected is an unknown function of ... |
| CVE-2025-9597 | CRITICAL | 9.8 | 0.4% | Aug 29, 2025 | A vulnerability was identified in itsourcecode Apartment Management System 1.0. This impacts an unknown function of the ... |
| CVE-2025-9596 | CRITICAL | 9.8 | 0.4% | Aug 29, 2025 | A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the fil... |
| CVE-2025-9594 | CRITICAL | 9.8 | 0.4% | Aug 28, 2025 | A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown funct... |
| CVE-2025-9593 | CRITICAL | 9.8 | 0.4% | Aug 28, 2025 | A flaw has been found in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /repo... |
| CVE-2025-9592 | CRITICAL | 9.8 | 0.5% | Aug 28, 2025 | A vulnerability was detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing... |
| CVE-2025-9582 | CRITICAL | 9.8 | 5.3% | Aug 28, 2025 | A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Execut... |
| CVE-2025-9581 | CRITICAL | 9.8 | 5.3% | Aug 28, 2025 | A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt.... |
| CVE-2025-58059 | CRITICAL | 9.1 | 0.4% | Aug 28, 2025 | Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to be... |
| CVE-2025-58048 | CRITICAL | 9.9 | 0.4% | Aug 28, 2025 | Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments funct... |
| CVE-2025-57819 | CRITICAL | 9.8 | 93.3% | Aug 28, 2025 | FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to ins... |
| CVE-2025-55583 | CRITICAL | 9.8 | 5.8% | Aug 28, 2025 | D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in... |
| CVE-2025-54738 | CRITICAL | 9.8 | 0.4% | Aug 28, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Auth... |
| CVE-2025-54725 | CRITICAL | 9.8 | 0.4% | Aug 28, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.Th... |
| CVE-2025-54720 | CRITICAL | 9.3 | 0.3% | Aug 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest A... |
| CVE-2025-52761 | CRITICAL | 9.8 | 0.4% | Aug 28, 2025 | Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection... |
| CVE-2025-49388 | CRITICAL | 9.8 | 5.0% | Aug 28, 2025 | Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Esca... |
| CVE-2025-49387 | CRITICAL | 10 | 0.4% | Aug 28, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor For... |
| CVE-2025-48100 | CRITICAL | 9.1 | 0.3% | Aug 28, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbu... |
| CVE-2025-39496 | CRITICAL | 9.3 | 0.3% | Aug 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Produ... |
| CVE-2025-54762 | CRITICAL | 9.8 | 0.5% | Aug 28, 2025 | SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb... |
| CVE-2025-53970 | CRITICAL | 9.8 | 0.5% | Aug 28, 2025 | SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb... |
| CVE-2025-7955 | CRITICAL | 9.8 | 0.7% | Aug 28, 2025 | The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi... |
| CVE-2025-34523 | CRITICAL | 9.8 | 0.5% | Aug 27, 2025 | A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now