2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56572 | HIGH | 7.5 | 0.5% | Sep 30, 2025 | An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter. |
| CVE-2025-56571 | HIGH | 7.5 | 0.4% | Sep 30, 2025 | Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper hand... |
| CVE-2025-7779 | HIGH | 8.8 | 0.1% | Sep 30, 2025 | Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True ... |
| CVE-2025-56301 | HIGH | 7.5 | 0.6% | Sep 30, 2025 | An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowi... |
| CVE-2025-11178 | HIGH | 7.3 | 0.2% | Sep 30, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (... |
| CVE-2025-9230 | HIGH | 7.5 | 1.7% | Sep 30, 2025 | Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an ou... |
| CVE-2025-11153 | HIGH | 7.5 | 0.2% | Sep 30, 2025 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3. |
| CVE-2025-11152 | HIGH | 8.6 | 0.3% | Sep 30, 2025 | Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.... |
| CVE-2025-9993 | HIGH | 8.1 | 0.7% | Sep 30, 2025 | The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ... |
| CVE-2025-9991 | HIGH | 8.1 | 0.6% | Sep 30, 2025 | The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ... |
| CVE-2025-8877 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in... |
| CVE-2025-8122 | HIGH | 8.8 | 0.3% | Sep 30, 2025 | Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ... |
| CVE-2025-8121 | HIGH | 8.8 | 0.3% | Sep 30, 2025 | Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ... |
| CVE-2025-8117 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that d... |
| CVE-2025-7052 | HIGH | 8.8 | 0.2% | Sep 30, 2025 | The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1... |
| CVE-2025-7038 | HIGH | 8.2 | 0.4% | Sep 30, 2025 | The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification with... |
| CVE-2025-59668 | HIGH | 8.7 | 0.4% | Sep 30, 2025 | Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafte... |
| CVE-2025-41098 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-11149 | HIGH | 7.5 | 0.5% | Sep 30, 2025 | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package... |
| CVE-2025-10991 | HIGH | 7 | 0.2% | Sep 30, 2025 | The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have ... |
| CVE-2025-59952 | HIGH | 8.7 | 0.5% | Sep 30, 2025 | MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 comp... |
| CVE-2025-59942 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it v... |
| CVE-2025-43813 | HIGH | 8.2 | 0.5% | Sep 29, 2025 | Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.10... |
| CVE-2025-36245 | HIGH | 8.8 | 0.4% | Sep 29, 2025 | IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary comma... |
| CVE-2025-59933 | HIGH | 7.8 | 0.2% | Sep 29, 2025 | libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now