2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58012 | LOW | 3.8 | 0.3% | Sep 22, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Alex Content Mask content-mask allows Exploiting Incor... |
| CVE-2025-58009 | LOW | 3.8 | 0.3% | Sep 22, 2025 | Missing Authorization vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Exploiting... |
| CVE-2025-10778 | LOW | 3.1 | 0.2% | Sep 22, 2025 | A vulnerability has been found in Smartstore up to 6.2.0. The affected element is an unknown function of the file /check... |
| CVE-2025-10776 | LOW | 3.7 | 0.2% | Sep 22, 2025 | A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the co... |
| CVE-2025-10761 | LOW | 3.7 | 0.5% | Sep 21, 2025 | A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api/v1/login of the compon... |
| CVE-2025-59427 | LOW | 2.9 | 0.4% | Sep 19, 2025 | The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the ... |
| CVE-2025-59692 | LOW | 3.7 | 0.2% | Sep 18, 2025 | PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing ipta... |
| CVE-2025-59691 | LOW | 3.7 | 0.2% | Sep 18, 2025 | PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon netwo... |
| CVE-2025-10650 | LOW | 1.8 | 0.1% | Sep 18, 2025 | SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys und... |
| CVE-2025-59421 | LOW | 2.7 | 0.4% | Sep 18, 2025 | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-... |
| CVE-2025-10671 | LOW | 3.7 | 0.4% | Sep 18, 2025 | A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of t... |
| CVE-2025-30187 | LOW | 3.7 | 0.3% | Sep 18, 2025 | In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries,... |
| CVE-2025-59410 | LOW | 3.7 | 0.1% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the s... |
| CVE-2025-59349 | LOW | 3.3 | 0.1% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, DragonFly2 uses t... |
| CVE-2025-59414 | LOW | 3.1 | 0.3% | Sep 17, 2025 | Nuxt is an open-source web development framework for Vue.js. Prior to 3.19.0 and 4.1.0, A client-side path traversal vul... |
| CVE-2025-59161 | LOW | 2.7 | 0.4% | Sep 16, 2025 | Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11... |
| CVE-2025-59160 | LOW | 2.7 | 0.2% | Sep 16, 2025 | Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insuf... |
| CVE-2025-30075 | LOW | 2.2 | 0.1% | Sep 16, 2025 | In Alludo MindManager before 25.0.208 on Windows, attackers could potentially execute code as other local users on the s... |
| CVE-2025-59270 | LOW | 3.1 | 0.2% | Sep 16, 2025 | psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML au... |
| CVE-2025-26710 | LOW | 3.5 | 0.2% | Sep 16, 2025 | There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control me... |
| CVE-2025-10316 | LOW | 2.3 | 0.3% | Sep 16, 2025 | The extension "Form to Database" is susceptible to Cross-Site Scripting. This issue affects the following versions: befo... |
| CVE-2025-59453 | LOW | 3.2 | 0.1% | Sep 16, 2025 | Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency acce... |
| CVE-2025-59437 | LOW | 3.2 | 0.1% | Sep 16, 2025 | The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly catego... |
| CVE-2025-59436 | LOW | 3.2 | 0.1% | Sep 16, 2025 | The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improp... |
| CVE-2025-43357 | LOW | 3.3 | 0.2% | Sep 15, 2025 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now