2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58013 | HIGH | 8.8 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affe... |
| CVE-2025-57977 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-inv... |
| CVE-2025-57968 | HIGH | 7.1 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestau... |
| CVE-2025-57925 | HIGH | 7.5 | 0.5% | Sep 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-57919 | HIGH | 7.2 | 0.6% | Sep 22, 2025 | Deserialization of Untrusted Data vulnerability in ConveyThis ConveyThis conveythis-translate allows Object Injection.Th... |
| CVE-2025-57918 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ERA404 LinkedInclude linkedinclude allows Stored XSS.This issue affec... |
| CVE-2025-57685 | HIGH | 8.8 | 1.4% | Sep 22, 2025 | The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, B... |
| CVE-2025-53468 | HIGH | 8.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus@hotmail.c... |
| CVE-2025-53465 | HIGH | 7.2 | 0.6% | Sep 22, 2025 | Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This ... |
| CVE-2025-53450 | HIGH | 7.5 | 0.6% | Sep 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59420 | HIGH | 7.5 | 0.2% | Sep 22, 2025 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific... |
| CVE-2025-57440 | HIGH | 7.5 | 0.3% | Sep 22, 2025 | The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated ... |
| CVE-2025-57439 | HIGH | 8.8 | 0.8% | Sep 22, 2025 | Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpo... |
| CVE-2025-55888 | HIGH | 7.3 | 0.5% | Sep 22, 2025 | Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can... |
| CVE-2025-43953 | HIGH | 8.8 | 7.1% | Sep 22, 2025 | In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or tr... |
| CVE-2025-59335 | HIGH | 7.1 | 0.2% | Sep 22, 2025 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration... |
| CVE-2025-57434 | HIGH | 8.8 | 0.5% | Sep 22, 2025 | Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The... |
| CVE-2025-57431 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malici... |
| CVE-2025-10807 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. This issue affects some unk... |
| CVE-2025-10806 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. This vulnerability affects unkno... |
| CVE-2025-57605 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users ... |
| CVE-2025-57430 | HIGH | 7.5 | 0.4% | Sep 22, 2025 | Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When access... |
| CVE-2025-36202 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute co... |
| CVE-2025-35041 | HIGH | 7.7 | 0.3% | Sep 22, 2025 | Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A r... |
| CVE-2025-10805 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A vulnerability was determined in Campcodes Online Beauty Parlor Management System 1.0. This affects an unknown part of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now