2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11078 | HIGH | 8.8 | 0.3% | Sep 27, 2025 | A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown ... |
| CVE-2025-11071 | HIGH | 7.2 | 0.3% | Sep 27, 2025 | A security vulnerability has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admin_c... |
| CVE-2025-8014 | HIGH | 7.5 | 0.6% | Sep 27, 2025 | Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 pri... |
| CVE-2025-7647 | HIGH | 7.3 | 0.1% | Sep 27, 2025 | The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a ... |
| CVE-2025-11054 | HIGH | 8.8 | 0.4% | Sep 27, 2025 | A security vulnerability has been detected in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function ... |
| CVE-2025-9816 | HIGH | 7.2 | 9.1% | Sep 27, 2025 | The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2025-3193 | HIGH | 7.5 | 0.5% | Sep 27, 2025 | Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in t... |
| CVE-2025-11050 | HIGH | 8.8 | 0.3% | Sep 27, 2025 | A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. E... |
| CVE-2025-10954 | HIGH | 7.5 | 0.4% | Sep 27, 2025 | Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic ... |
| CVE-2025-11049 | HIGH | 8.8 | 0.3% | Sep 27, 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of ... |
| CVE-2025-59945 | HIGH | 8.1 | 0.3% | Sep 27, 2025 | SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated ... |
| CVE-2025-59939 | HIGH | 8.8 | 0.3% | Sep 27, 2025 | WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks... |
| CVE-2025-59932 | HIGH | 8.2 | 0.3% | Sep 27, 2025 | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previo... |
| CVE-2025-59845 | HIGH | 8.2 | 0.1% | Sep 26, 2025 | Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Pr... |
| CVE-2025-11048 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unkno... |
| CVE-2025-11047 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Ap... |
| CVE-2025-11045 | HIGH | 7.3 | 2.0% | Sep 26, 2025 | A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function ... |
| CVE-2025-10657 | HIGH | 8.7 | 0.1% | Sep 26, 2025 | In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/ha... |
| CVE-2025-11041 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A vulnerability has been found in itsourcecode Open Source Job Portal 1.0. Affected by this issue is some unknown functi... |
| CVE-2025-11038 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A weakness has been identified in itsourcecode Online Clinic Management System 1.0. Affected is an unknown function of t... |
| CVE-2025-56383 | HIGH | 8.4 | 0.3% | Sep 26, 2025 | Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. N... |
| CVE-2025-55847 | HIGH | 8.8 | 1.9% | Sep 26, 2025 | Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerab... |
| CVE-2025-45994 | HIGH | 7.5 | 0.4% | Sep 26, 2025 | An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a... |
| CVE-2025-59844 | HIGH | 7.7 | 1.5% | Sep 26, 2025 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command ... |
| CVE-2025-55848 | HIGH | 8.8 | 0.4% | Sep 26, 2025 | An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interfa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now