2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41000 | LOW | 2.1 | 0.3% | Sep 3, 2025 | Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits... |
| CVE-2025-9821 | LOW | 2.7 | 0.3% | Sep 3, 2025 | SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, t... |
| CVE-2025-58272 | LOW | 3.7 | 0.1% | Sep 3, 2025 | Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views ... |
| CVE-2025-21040 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attacker... |
| CVE-2025-21039 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local... |
| CVE-2025-21038 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows loca... |
| CVE-2025-21029 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send... |
| CVE-2025-21026 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to int... |
| CVE-2025-7039 | LOW | 3.7 | 0.4% | Sep 3, 2025 | A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, al... |
| CVE-2025-8298 | LOW | 3.8 | 0.1% | Sep 2, 2025 | Realtek RTL8811AU rtwlanu.sys N6CQueryInformationHandleCustomized11nOids Out-Of-Bounds Read Information Disclosure Vulne... |
| CVE-2025-9797 | LOW | 2.4 | 0.2% | Sep 1, 2025 | A vulnerability was determined in mrvautin expressCart up to b31302f4e99c3293bd742c6d076a721e168118b0. This impacts an u... |
| CVE-2025-58160 | LOW | 2.3 | 0.3% | Aug 29, 2025 | tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior ... |
| CVE-2025-9071 | LOW | 2.3 | 0.2% | Aug 29, 2025 | Erroneously using an all-zero seed for RSA-OEAP padding instead of the generated random bytes, in Oberon microsystems AG... |
| CVE-2025-43255 | LOW | 3.3 | 0.2% | Aug 29, 2025 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sono... |
| CVE-2025-48979 | LOW | 3.4 | 0.4% | Aug 29, 2025 | An Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileg... |
| CVE-2025-9591 | LOW | 2.4 | 0.3% | Aug 28, 2025 | A security vulnerability has been detected in ZrLog up to 3.1.5. This vulnerability affects unknown code of the file /ap... |
| CVE-2025-9590 | LOW | 3.5 | 0.2% | Aug 28, 2025 | A vulnerability was identified in Weaver E-Mobile Mobile Management Platform up to 20250813. Affected by this vulnerabil... |
| CVE-2025-9589 | LOW | 2.5 | 0.1% | Aug 28, 2025 | A vulnerability was determined in Cudy WR1200EA 2.3.7-20250113-121810. Affected is an unknown function of the file /etc/... |
| CVE-2025-51643 | LOW | 2.4 | 0.2% | Aug 28, 2025 | Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentic... |
| CVE-2025-9514 | LOW | 3.7 | 0.4% | Aug 27, 2025 | A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registr... |
| CVE-2025-25733 | LOW | 3.5 | 0.2% | Aug 26, 2025 | Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829... |
| CVE-2025-8447 | LOW | 3.1 | 0.3% | Aug 26, 2025 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to an... |
| CVE-2025-9416 | LOW | 2.4 | 0.3% | Aug 25, 2025 | A security flaw has been discovered in oitcode samarium up to 0.9.6. This vulnerability affects unknown code of the file... |
| CVE-2025-3456 | LOW | 3.8 | 0.1% | Aug 25, 2025 | On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in... |
| CVE-2025-9401 | LOW | 3.7 | 0.4% | Aug 25, 2025 | A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now