2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56392 | HIGH | 8.1 | 0.3% | Sep 30, 2025 | An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attack... |
| CVE-2025-56132 | HIGH | 7.3 | 0.6% | Sep 30, 2025 | LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The appli... |
| CVE-2025-23293 | HIGH | 8.7 | 0.2% | Sep 30, 2025 | NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause... |
| CVE-2025-6034 | HIGH | 8.5 | 0.2% | Sep 30, 2025 | There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor ... |
| CVE-2025-6033 | HIGH | 8.5 | 0.2% | Sep 30, 2025 | There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in N... |
| CVE-2025-56572 | HIGH | 7.5 | 0.5% | Sep 30, 2025 | An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter. |
| CVE-2025-56571 | HIGH | 7.5 | 0.4% | Sep 30, 2025 | Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper hand... |
| CVE-2025-7779 | HIGH | 8.8 | 0.1% | Sep 30, 2025 | Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True ... |
| CVE-2025-56301 | HIGH | 7.5 | 0.6% | Sep 30, 2025 | An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowi... |
| CVE-2025-11178 | HIGH | 7.3 | 0.2% | Sep 30, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (... |
| CVE-2025-9230 | HIGH | 7.5 | 1.7% | Sep 30, 2025 | Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an ou... |
| CVE-2025-11153 | HIGH | 7.5 | 0.2% | Sep 30, 2025 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3. |
| CVE-2025-11152 | HIGH | 8.6 | 0.3% | Sep 30, 2025 | Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.... |
| CVE-2025-9993 | HIGH | 8.1 | 0.7% | Sep 30, 2025 | The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ... |
| CVE-2025-9991 | HIGH | 8.1 | 0.6% | Sep 30, 2025 | The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ... |
| CVE-2025-8877 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in... |
| CVE-2025-8122 | HIGH | 8.8 | 0.3% | Sep 30, 2025 | Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ... |
| CVE-2025-8121 | HIGH | 8.8 | 0.3% | Sep 30, 2025 | Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ... |
| CVE-2025-8117 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that d... |
| CVE-2025-7052 | HIGH | 8.8 | 0.2% | Sep 30, 2025 | The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1... |
| CVE-2025-7038 | HIGH | 8.2 | 0.4% | Sep 30, 2025 | The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification with... |
| CVE-2025-59668 | HIGH | 8.7 | 0.4% | Sep 30, 2025 | Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafte... |
| CVE-2025-41098 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-11149 | HIGH | 7.5 | 0.5% | Sep 30, 2025 | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package... |
| CVE-2025-10991 | HIGH | 7 | 0.2% | Sep 30, 2025 | The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now