2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59952 | HIGH | 8.7 | 0.5% | Sep 30, 2025 | MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 comp... |
| CVE-2025-59942 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it v... |
| CVE-2025-43813 | HIGH | 8.2 | 0.5% | Sep 29, 2025 | Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.10... |
| CVE-2025-36245 | HIGH | 8.8 | 0.4% | Sep 29, 2025 | IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary comma... |
| CVE-2025-59933 | HIGH | 7.8 | 0.2% | Sep 29, 2025 | libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips ... |
| CVE-2025-54591 | HIGH | 7.5 | 0.4% | Sep 29, 2025 | FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of d... |
| CVE-2025-45376 | HIGH | 7.8 | 0.1% | Sep 29, 2025 | Dell Repository Manager (DRM), versions 3.4.7 and 3.4.8, contains an Improper Handling of Insufficient Permissions or Pr... |
| CVE-2025-34235 | HIGH | 7.8 | 0.4% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2... |
| CVE-2025-34234 | HIGH | 7.5 | 0.4% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2... |
| CVE-2025-34231 | HIGH | 8.6 | 0.7% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2... |
| CVE-2025-34228 | HIGH | 8.6 | 0.7% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2... |
| CVE-2025-34225 | HIGH | 8.6 | 0.8% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2... |
| CVE-2025-34209 | HIGH | 7.2 | 0.7% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.862 and Application prior to 20.0.2014 (VA and... |
| CVE-2025-35030 | HIGH | 8.8 | 0.2% | Sep 29, 2025 | Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthen... |
| CVE-2025-57424 | HIGH | 7.3 | 0.2% | Sep 29, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile fi... |
| CVE-2025-41252 | HIGH | 7.5 | 0.9% | Sep 29, 2025 | Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit th... |
| CVE-2025-41251 | HIGH | 8.1 | 1.0% | Sep 29, 2025 | VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit thi... |
| CVE-2025-57483 | HIGH | 8.1 | 0.3% | Sep 29, 2025 | A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary ... |
| CVE-2025-41250 | HIGH | 8.5 | 0.6% | Sep 29, 2025 | VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on ... |
| CVE-2025-7104 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attac... |
| CVE-2025-56234 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST p... |
| CVE-2025-56233 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN ... |
| CVE-2025-51495 | HIGH | 7.5 | 0.4% | Sep 29, 2025 | An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially cr... |
| CVE-2025-41244 | HIGH | 7.8 | 7.9% | Sep 29, 2025 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with... |
| CVE-2025-41246 | HIGH | 7.6 | 0.3% | Sep 29, 2025 | VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now