2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11030 | HIGH | 7.3 | 0.4% | Sep 26, 2025 | A vulnerability was detected in Tutorials-Website Employee Management System up to 611887d8f8375271ce8abc704507d46340837... |
| CVE-2025-11029 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipul... |
| CVE-2025-58385 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (th... |
| CVE-2025-11028 | HIGH | 7.5 | 0.6% | Sep 26, 2025 | A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image H... |
| CVE-2025-36326 | HIGH | 7.5 | 0.2% | Sep 26, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain ... |
| CVE-2025-36274 | HIGH | 7.5 | 0.2% | Sep 26, 2025 | IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which ... |
| CVE-2025-11026 | HIGH | 7.5 | 0.3% | Sep 26, 2025 | A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality... |
| CVE-2025-11018 | HIGH | 7.5 | 0.9% | Sep 26, 2025 | A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of ... |
| CVE-2025-9267 | HIGH | 7 | 0.2% | Sep 26, 2025 | In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attemp... |
| CVE-2025-11014 | HIGH | 7.8 | 0.2% | Sep 26, 2025 | A security flaw has been discovered in OGRECave Ogre up to 14.4.1. This issue affects the function STBIImageCodec::encod... |
| CVE-2025-11012 | HIGH | 7.8 | 0.2% | Sep 26, 2025 | A vulnerability was determined in BehaviorTree up to 4.7.0. This affects the function ParseScript of the file /src/scrip... |
| CVE-2025-11042 | HIGH | 7.5 | 0.3% | Sep 26, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and... |
| CVE-2025-10544 | HIGH | 8.6 | 0.3% | Sep 26, 2025 | Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versio... |
| CVE-2025-9958 | HIGH | 7.7 | 0.5% | Sep 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18... |
| CVE-2025-7691 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 pri... |
| CVE-2025-60173 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce gst-for-woocommerce allows Stored X... |
| CVE-2025-60172 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in flytedesk Flytedesk Digital flytedesk-digital allows Stored XSS.This ... |
| CVE-2025-60171 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce – YourPlugins.c... |
| CVE-2025-60170 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Taraprasad Swain HTACCESS IP Blocker htaccess-ip-blocker allows Store... |
| CVE-2025-60169 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho... |
| CVE-2025-60164 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in NewsMAN NewsmanApp newsmanapp allows Stored XSS.This issue affects Ne... |
| CVE-2025-60153 | HIGH | 7.5 | 0.4% | Sep 26, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-60150 | HIGH | 7.5 | 0.4% | Sep 26, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-60126 | HIGH | 8.8 | 0.4% | Sep 26, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-60118 | HIGH | 8.5 | 0.3% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Potenzaglobalsolut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now