2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56383 | HIGH | 8.4 | 0.3% | Sep 26, 2025 | Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. N... |
| CVE-2025-55847 | HIGH | 8.8 | 1.9% | Sep 26, 2025 | Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerab... |
| CVE-2025-45994 | HIGH | 7.5 | 0.4% | Sep 26, 2025 | An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a... |
| CVE-2025-59844 | HIGH | 7.7 | 1.5% | Sep 26, 2025 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command ... |
| CVE-2025-55848 | HIGH | 8.8 | 0.4% | Sep 26, 2025 | An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interfa... |
| CVE-2025-11030 | HIGH | 7.3 | 0.4% | Sep 26, 2025 | A vulnerability was detected in Tutorials-Website Employee Management System up to 611887d8f8375271ce8abc704507d46340837... |
| CVE-2025-11029 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipul... |
| CVE-2025-58385 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (th... |
| CVE-2025-11028 | HIGH | 7.5 | 0.6% | Sep 26, 2025 | A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image H... |
| CVE-2025-36326 | HIGH | 7.5 | 0.2% | Sep 26, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain ... |
| CVE-2025-36274 | HIGH | 7.5 | 0.2% | Sep 26, 2025 | IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which ... |
| CVE-2025-11026 | HIGH | 7.5 | 0.3% | Sep 26, 2025 | A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality... |
| CVE-2025-11018 | HIGH | 7.5 | 0.9% | Sep 26, 2025 | A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of ... |
| CVE-2025-9267 | HIGH | 7 | 0.2% | Sep 26, 2025 | In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attemp... |
| CVE-2025-11014 | HIGH | 7.8 | 0.2% | Sep 26, 2025 | A security flaw has been discovered in OGRECave Ogre up to 14.4.1. This issue affects the function STBIImageCodec::encod... |
| CVE-2025-11012 | HIGH | 7.8 | 0.2% | Sep 26, 2025 | A vulnerability was determined in BehaviorTree up to 4.7.0. This affects the function ParseScript of the file /src/scrip... |
| CVE-2025-11042 | HIGH | 7.5 | 0.3% | Sep 26, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and... |
| CVE-2025-10544 | HIGH | 8.6 | 0.3% | Sep 26, 2025 | Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versio... |
| CVE-2025-9958 | HIGH | 7.7 | 0.5% | Sep 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18... |
| CVE-2025-7691 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 pri... |
| CVE-2025-60173 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce gst-for-woocommerce allows Stored X... |
| CVE-2025-60172 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in flytedesk Flytedesk Digital flytedesk-digital allows Stored XSS.This ... |
| CVE-2025-60171 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce – YourPlugins.c... |
| CVE-2025-60170 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Taraprasad Swain HTACCESS IP Blocker htaccess-ip-blocker allows Store... |
| CVE-2025-60169 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now