2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40803 | LOW | 3.1 | 0.2% | Sep 9, 2025 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes ce... |
| CVE-2025-9111 | LOW | 3.5 | 0.2% | Sep 9, 2025 | The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which cou... |
| CVE-2025-8889 | LOW | 3.8 | 0.3% | Sep 9, 2025 | The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege u... |
| CVE-2025-42927 | LOW | 3.4 | 0.1% | Sep 9, 2025 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful... |
| CVE-2025-42914 | LOW | 3.1 | 0.2% | Sep 9, 2025 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in... |
| CVE-2025-42913 | LOW | 3.1 | 0.2% | Sep 9, 2025 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in... |
| CVE-2025-51586 | LOW | 3.7 | 0.8% | Sep 8, 2025 | An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers ... |
| CVE-2025-58422 | LOW | 3.1 | 0.1% | Sep 8, 2025 | RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perfor... |
| CVE-2025-10080 | LOW | 3.1 | 0.2% | Sep 8, 2025 | A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTok... |
| CVE-2025-0011 | LOW | 3.3 | 0.2% | Sep 6, 2025 | Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to ob... |
| CVE-2025-10014 | LOW | 3.1 | 0.3% | Sep 5, 2025 | A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/upda... |
| CVE-2025-26461 | LOW | 3.3 | 0.1% | Sep 5, 2025 | In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the u... |
| CVE-2025-58866 | LOW | 2.7 | 0.2% | Sep 5, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami Yushuvaev Site Info sit... |
| CVE-2025-58827 | LOW | 3.8 | 0.2% | Sep 5, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manag... |
| CVE-2025-58816 | LOW | 3.5 | 0.2% | Sep 5, 2025 | Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor ecommerce-product-carousel-slid... |
| CVE-2025-58313 | LOW | 2.5 | 0.1% | Sep 5, 2025 | Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cau... |
| CVE-2025-26419 | LOW | 3.3 | 0.1% | Sep 4, 2025 | In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This... |
| CVE-2025-0076 | LOW | 3.3 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to view icons belonging to another user due to a missing permission check... |
| CVE-2025-26428 | LOW | 3.2 | 0.1% | Sep 4, 2025 | In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code... |
| CVE-2025-58064 | LOW | 2.3 | 0.4% | Sep 4, 2025 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions ... |
| CVE-2025-41000 | LOW | 2.1 | 0.3% | Sep 3, 2025 | Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits... |
| CVE-2025-9821 | LOW | 2.7 | 0.3% | Sep 3, 2025 | SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, t... |
| CVE-2025-58272 | LOW | 3.7 | 0.1% | Sep 3, 2025 | Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views ... |
| CVE-2025-21040 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attacker... |
| CVE-2025-21039 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now