2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58261 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc Mavis HTTPS to HTTP Redirection mavis-htt... |
| CVE-2025-58259 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in scriptsbundle Nokri nokri allows Cross Site Request Forgery.This issu... |
| CVE-2025-58250 | HIGH | 8.8 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo fingo allows Authentication Bypass.This issue affect... |
| CVE-2025-58244 | HIGH | 8.8 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo constructo allows Object Injection.This issue affects... |
| CVE-2025-58015 | HIGH | 7.5 | 0.3% | Sep 22, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Ays Pro Quiz Maker quiz-make... |
| CVE-2025-58013 | HIGH | 8.8 | 0.2% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affe... |
| CVE-2025-57977 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-inv... |
| CVE-2025-57968 | HIGH | 7.1 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestau... |
| CVE-2025-57925 | HIGH | 7.5 | 0.5% | Sep 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-57919 | HIGH | 7.2 | 0.6% | Sep 22, 2025 | Deserialization of Untrusted Data vulnerability in ConveyThis ConveyThis conveythis-translate allows Object Injection.Th... |
| CVE-2025-57918 | HIGH | 7.1 | 0.1% | Sep 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ERA404 LinkedInclude linkedinclude allows Stored XSS.This issue affec... |
| CVE-2025-57685 | HIGH | 8.8 | 1.4% | Sep 22, 2025 | The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, B... |
| CVE-2025-53468 | HIGH | 8.5 | 0.3% | Sep 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus@hotmail.c... |
| CVE-2025-53465 | HIGH | 7.2 | 0.6% | Sep 22, 2025 | Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This ... |
| CVE-2025-53450 | HIGH | 7.5 | 0.6% | Sep 22, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-59420 | HIGH | 7.5 | 0.2% | Sep 22, 2025 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific... |
| CVE-2025-57440 | HIGH | 7.5 | 0.3% | Sep 22, 2025 | The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated ... |
| CVE-2025-57439 | HIGH | 8.8 | 0.8% | Sep 22, 2025 | Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpo... |
| CVE-2025-55888 | HIGH | 7.3 | 0.5% | Sep 22, 2025 | Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can... |
| CVE-2025-43953 | HIGH | 8.8 | 7.1% | Sep 22, 2025 | In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or tr... |
| CVE-2025-59335 | HIGH | 7.1 | 0.2% | Sep 22, 2025 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration... |
| CVE-2025-57434 | HIGH | 8.8 | 0.5% | Sep 22, 2025 | Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The... |
| CVE-2025-57431 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malici... |
| CVE-2025-10807 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. This issue affects some unk... |
| CVE-2025-10806 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. This vulnerability affects unkno... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now