2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10804 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A vulnerability was found in Campcodes Online Beauty Parlor Management System 1.0. Affected by this issue is some unknow... |
| CVE-2025-9038 | HIGH | 7.5 | 0.1% | Sep 22, 2025 | Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Es... |
| CVE-2025-10803 | HIGH | 8.8 | 0.7% | Sep 22, 2025 | A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of... |
| CVE-2025-51006 | HIGH | 7.8 | 0.2% | Sep 22, 2025 | Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function i... |
| CVE-2025-10854 | HIGH | 8.1 | 0.4% | Sep 22, 2025 | The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is inte... |
| CVE-2025-9983 | HIGH | 7.1 | 0.6% | Sep 22, 2025 | GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated cr... |
| CVE-2025-10792 | HIGH | 8.8 | 3.0% | Sep 22, 2025 | A security vulnerability has been detected in D-Link DIR-513 A1FW110. Affected is an unknown function of the file /gofor... |
| CVE-2025-10009 | HIGH | 8.6 | 0.5% | Sep 22, 2025 | Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with a... |
| CVE-2025-10790 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | A security flaw has been discovered in SourceCodester Simple Forum Discussion System 1.0. This affects an unknown functi... |
| CVE-2025-5962 | HIGH | 7.7 | 0.2% | Sep 22, 2025 | A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to acc... |
| CVE-2025-10780 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | A vulnerability was determined in CodeAstro Simple Pharmacy Management 1.0. This affects an unknown function of the file... |
| CVE-2025-10775 | HIGH | 7.2 | 20.0% | Sep 22, 2025 | A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_401... |
| CVE-2025-10773 | HIGH | 8.8 | 3.7% | Sep 22, 2025 | A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath o... |
| CVE-2025-53692 | HIGH | 7.1 | 0.4% | Sep 21, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Si... |
| CVE-2025-10765 | HIGH | 7.2 | 0.4% | Sep 21, 2025 | A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Sug... |
| CVE-2025-10764 | HIGH | 8.8 | 0.4% | Sep 21, 2025 | A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.Eve... |
| CVE-2025-10757 | HIGH | 8.8 | 1.0% | Sep 21, 2025 | A weakness has been identified in UTT 1200GW up to 3.0.0-170831. The affected element is an unknown function of the file... |
| CVE-2025-10756 | HIGH | 8.8 | 0.8% | Sep 20, 2025 | A security flaw has been discovered in UTT HiPER 840G up to 3.1.1-190328. Impacted is an unknown function of the file /g... |
| CVE-2025-9079 | HIGH | 7.2 | 0.6% | Sep 19, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to ... |
| CVE-2025-54815 | HIGH | 8.8 | 0.6% | Sep 19, 2025 | Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via craft... |
| CVE-2025-54761 | HIGH | 8 | 0.3% | Sep 19, 2025 | An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie. |
| CVE-2025-52159 | HIGH | 8.8 | 0.4% | Sep 19, 2025 | Hardcoded credentials in default configuration of PPress 0.0.9. |
| CVE-2025-34202 | HIGH | 8.8 | 0.9% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and... |
| CVE-2025-34201 | HIGH | 7.8 | 0.3% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker co... |
| CVE-2025-34200 | HIGH | 7.8 | 0.3% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the app... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now