2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10246 | LOW | 3.5 | 0.2% | Sep 11, 2025 | A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b... |
| CVE-2025-6088 | LOW | 3.1 | 0.3% | Sep 11, 2025 | In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow una... |
| CVE-2025-10216 | LOW | 2.6 | 0.2% | Sep 10, 2025 | A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout... |
| CVE-2025-8277 | LOW | 3.1 | 0.4% | Sep 9, 2025 | A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guess... |
| CVE-2025-59014 | LOW | 2.7 | 0.3% | Sep 9, 2025 | An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 l... |
| CVE-2025-40803 | LOW | 3.1 | 0.2% | Sep 9, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes ce... |
| CVE-2025-9111 | LOW | 3.5 | 0.2% | Sep 9, 2025 | The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which cou... |
| CVE-2025-8889 | LOW | 3.8 | 0.3% | Sep 9, 2025 | The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege u... |
| CVE-2025-42927 | LOW | 3.4 | 0.1% | Sep 9, 2025 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful... |
| CVE-2025-42914 | LOW | 3.1 | 0.2% | Sep 9, 2025 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in... |
| CVE-2025-42913 | LOW | 3.1 | 0.2% | Sep 9, 2025 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in... |
| CVE-2025-51586 | LOW | 3.7 | 0.8% | Sep 8, 2025 | An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers ... |
| CVE-2025-58422 | LOW | 3.1 | 0.1% | Sep 8, 2025 | RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perfor... |
| CVE-2025-10080 | LOW | 3.1 | 0.2% | Sep 8, 2025 | A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTok... |
| CVE-2025-0011 | LOW | 3.3 | 0.2% | Sep 6, 2025 | Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to ob... |
| CVE-2025-10014 | LOW | 3.1 | 0.3% | Sep 5, 2025 | A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/upda... |
| CVE-2025-26461 | LOW | 3.3 | 0.1% | Sep 5, 2025 | In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the u... |
| CVE-2025-58866 | LOW | 2.7 | 0.2% | Sep 5, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami Yushuvaev Site Info sit... |
| CVE-2025-58827 | LOW | 3.8 | 0.2% | Sep 5, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manag... |
| CVE-2025-58816 | LOW | 3.5 | 0.2% | Sep 5, 2025 | Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor ecommerce-product-carousel-slid... |
| CVE-2025-58313 | LOW | 2.5 | 0.1% | Sep 5, 2025 | Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cau... |
| CVE-2025-26419 | LOW | 3.3 | 0.1% | Sep 4, 2025 | In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This... |
| CVE-2025-0076 | LOW | 3.3 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to view icons belonging to another user due to a missing permission check... |
| CVE-2025-26428 | LOW | 3.2 | 0.1% | Sep 4, 2025 | In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code... |
| CVE-2025-58064 | LOW | 2.3 | 0.4% | Sep 4, 2025 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now