2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10942 | HIGH | 8.8 | 0.7% | Sep 25, 2025 | A vulnerability was identified in H3C Magic B3 up to 100R002. This affects the function AddMacList/EditMacList of the fi... |
| CVE-2025-10941 | HIGH | 8.5 | 0.1% | Sep 25, 2025 | A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functi... |
| CVE-2025-10438 | HIGH | 8.6 | 0.4% | Sep 25, 2025 | Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical ... |
| CVE-2025-54520 | HIGH | 8.6 | 0.2% | Sep 24, 2025 | Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to ... |
| CVE-2025-59833 | HIGH | 7.5 | 0.3% | Sep 24, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/probl... |
| CVE-2025-57319 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedR... |
| CVE-2025-57318 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject prop... |
| CVE-2025-57329 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability i... |
| CVE-2025-57328 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | toggle-array is a package designed to enables a property on the object at the specified index, while disabling the prope... |
| CVE-2025-57327 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config funct... |
| CVE-2025-57326 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers ... |
| CVE-2025-57325 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes a... |
| CVE-2025-57323 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vul... |
| CVE-2025-59251 | HIGH | 7.6 | 0.5% | Sep 24, 2025 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-57349 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable ... |
| CVE-2025-57330 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in ... |
| CVE-2025-55322 | HIGH | 7.3 | 0.3% | Sep 24, 2025 | Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network. |
| CVE-2025-59343 | HIGH | 8.7 | 0.5% | Sep 24, 2025 | tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink... |
| CVE-2025-59305 | HIGH | 7.6 | 0.3% | Sep 24, 2025 | Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated use... |
| CVE-2025-57350 | HIGH | 8.6 | 0.3% | Sep 24, 2025 | The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototy... |
| CVE-2025-56241 | HIGH | 7.5 | 6.3% | Sep 24, 2025 | Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the ... |
| CVE-2025-52907 | HIGH | 8.8 | 0.9% | Sep 24, 2025 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affect... |
| CVE-2025-48869 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded res... |
| CVE-2025-20352 | HIGH | 7.7 | 37.6% | Sep 24, 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa... |
| CVE-2025-20327 | HIGH | 7.7 | 0.4% | Sep 24, 2025 | A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now