2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59399 | LOW | 3.1 | 0.2% | Sep 15, 2025 | libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error me... |
| CVE-2025-59398 | LOW | 3.1 | 0.2% | Sep 15, 2025 | The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 2... |
| CVE-2025-36082 | LOW | 3.3 | 0.1% | Sep 15, 2025 | IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system. |
| CVE-2025-10434 | LOW | 2.4 | 0.2% | Sep 15, 2025 | A vulnerability was identified in IbuyuCMS up to 2.6.3. Impacted is an unknown function of the file /admin/article.php?a... |
| CVE-2025-10423 | LOW | 3.7 | 0.4% | Sep 15, 2025 | A vulnerability was found in newbee-mall 1.0. Impacted is the function mallKaptcha of the file /common/mall/kaptcha. The... |
| CVE-2025-0164 | LOW | 2.3 | 0.1% | Sep 14, 2025 | IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unautho... |
| CVE-2025-10388 | LOW | 3.5 | 0.2% | Sep 14, 2025 | A vulnerability was identified in Selleo Mentingo 2025.08.27. This issue affects some unknown processing of the file /ap... |
| CVE-2025-10340 | LOW | 3.5 | 0.2% | Sep 13, 2025 | A vulnerability was determined in WhatCD Gazelle up to 63b337026d49b5cf63ce4be20fdabdc880112fa3. The affected element is... |
| CVE-2025-4234 | LOW | 2.4 | 0.1% | Sep 12, 2025 | A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials ... |
| CVE-2025-10320 | LOW | 3.1 | 0.2% | Sep 12, 2025 | A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the f... |
| CVE-2025-27238 | LOW | 3.5 | 0.2% | Sep 12, 2025 | Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user gr... |
| CVE-2025-3650 | LOW | 3.5 | 0.2% | Sep 12, 2025 | The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes o... |
| CVE-2025-10287 | LOW | 3.1 | 0.2% | Sep 12, 2025 | A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element... |
| CVE-2025-56556 | LOW | 3.8 | 0.2% | Sep 11, 2025 | An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the buil... |
| CVE-2025-59047 | LOW | 2.7 | 0.4% | Sep 11, 2025 | matrix-sdk-base is the base component to build a Matrix client library. In matrix-sdk-base before 0.14.1, calling the `R... |
| CVE-2025-10255 | LOW | 3.5 | 0.3% | Sep 11, 2025 | A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the fi... |
| CVE-2025-10254 | LOW | 3.5 | 0.2% | Sep 11, 2025 | A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of ... |
| CVE-2025-10253 | LOW | 3.5 | 0.2% | Sep 11, 2025 | A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifi... |
| CVE-2025-10252 | LOW | 3.1 | 0.2% | Sep 11, 2025 | A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI ... |
| CVE-2025-10246 | LOW | 3.5 | 0.2% | Sep 11, 2025 | A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b... |
| CVE-2025-6088 | LOW | 3.1 | 0.3% | Sep 11, 2025 | In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow una... |
| CVE-2025-10216 | LOW | 2.6 | 0.2% | Sep 10, 2025 | A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout... |
| CVE-2025-10222 | LOW | 3.3 | 0.1% | Sep 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon... |
| CVE-2025-8277 | LOW | 3.1 | 0.4% | Sep 9, 2025 | A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guess... |
| CVE-2025-59014 | LOW | 2.7 | 0.3% | Sep 9, 2025 | An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 l... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now