2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11395 | MEDIUM | 5.5 | — | Sep 15, 2026 | A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create ... |
| CVE-2025-5802 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of use... |
| CVE-2025-24890 | MEDIUM | 6.8 | 0.2% | Sep 14, 2026 | gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats r... |
| CVE-2025-68624 | MEDIUM | 4.3 | 0.3% | Sep 14, 2026 | N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user ... |
| CVE-2025-63842 | MEDIUM | 5.4 | 0.2% | Sep 14, 2026 | A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote ... |
| CVE-2025-70819 | MEDIUM | 6.3 | 0.1% | Sep 13, 2026 | Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as ... |
| CVE-2025-69904 | MEDIUM | 4.9 | 0.4% | Sep 11, 2026 | Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on t... |
| CVE-2025-51619 | MEDIUM | 5.5 | — | Sep 9, 2026 | A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause... |
| CVE-2025-71418 | MEDIUM | 5.3 | — | Sep 9, 2026 | PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients ... |
| CVE-2025-71417 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_P... |
| CVE-2025-3271 | MEDIUM | 4.8 | 0.3% | Sep 9, 2026 | Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS |
| CVE-2025-46808 | MEDIUM | 6.8 | 0.2% | Sep 9, 2026 | An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive informatio... |
| CVE-2025-7062 | MEDIUM | 5.2 | 0.3% | Sep 9, 2026 | A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Edu... |
| CVE-2025-15690 | MEDIUM | 6.8 | 0.2% | Sep 9, 2026 | The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post bef... |
| CVE-2025-64868 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64866 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64854 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64838 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64830 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64618 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64610 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64589 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64588 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64584 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64542 | MEDIUM | 5.4 | 0.2% | Sep 8, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now