2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54086 | LOW | 3.3 | 0.2% | Oct 2, 2025 | CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to vers... |
| CVE-2025-58769 | LOW | 3.3 | 0.3% | Oct 1, 2025 | auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import... |
| CVE-2025-43718 | LOW | 2.9 | 0.1% | Oct 1, 2025 | Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within t... |
| CVE-2025-56675 | LOW | 3.5 | 0.2% | Sep 30, 2025 | The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers wi... |
| CVE-2025-23291 | LOW | 2.4 | 0.1% | Sep 30, 2025 | NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause... |
| CVE-2025-11195 | LOW | 3.3 | 0.1% | Sep 30, 2025 | Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can... |
| CVE-2025-59163 | LOW | 2.1 | 0.4% | Sep 29, 2025 | vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding a... |
| CVE-2025-55795 | LOW | 3.5 | 0.3% | Sep 29, 2025 | The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership v... |
| CVE-2025-11137 | LOW | 3.5 | 0.2% | Sep 29, 2025 | A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File... |
| CVE-2025-11134 | LOW | 2.4 | 0.2% | Sep 29, 2025 | A security vulnerability has been detected in Cudy TR1200 1.16.3-20230804-164635. Impacted is an unknown function of the... |
| CVE-2025-10173 | LOW | 2.7 | 0.2% | Sep 26, 2025 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable ... |
| CVE-2025-60019 | LOW | 3.7 | 0.3% | Sep 25, 2025 | glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memo... |
| CVE-2025-36857 | LOW | 3.3 | 0.1% | Sep 25, 2025 | Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's conf... |
| CVE-2025-10949 | LOW | 2.4 | 0.2% | Sep 25, 2025 | A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of... |
| CVE-2025-59422 | LOW | 3.1 | 0.2% | Sep 25, 2025 | Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /con... |
| CVE-2025-10909 | LOW | 2.4 | 0.3% | Sep 24, 2025 | A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the f... |
| CVE-2025-23346 | LOW | 3.3 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereferen... |
| CVE-2025-23340 | LOW | 3.3 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b... |
| CVE-2025-23271 | LOW | 3.3 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b... |
| CVE-2025-23255 | LOW | 3.3 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary where a user may cause an out-of-... |
| CVE-2025-23248 | LOW | 3.3 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b... |
| CVE-2025-0672 | LOW | 3.8 | 0.2% | Sep 23, 2025 | An authentication bypass vulnerability exists in multiple WSO2 products when FIDO authentication is enabled. When a user... |
| CVE-2025-8282 | LOW | 3.5 | 0.2% | Sep 23, 2025 | The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the pag... |
| CVE-2025-10823 | LOW | 3.3 | 0.1% | Sep 23, 2025 | A vulnerability was found in axboe fio up to 3.41. This affects the function str_buffer_pattern_cb of the file options.c... |
| CVE-2025-59526 | LOW | 2.7 | 0.4% | Sep 22, 2025 | mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Prior to version 2.0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now