2025 CVE Vulnerabilities
45,152 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7988 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-7987 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-7986 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-7985 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Cobalt VC6 File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows re... |
| CVE-2025-7984 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Cobalt AR File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-7983 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabili... |
| CVE-2025-7982 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows rem... |
| CVE-2025-7981 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Graphite VC6 File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability a... |
| CVE-2025-7980 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-7979 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil... |
| CVE-2025-7978 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Graphite VC6 File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability a... |
| CVE-2025-7977 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | Ashlar-Vellum Cobalt LI File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2025-10618 | HIGH | 8.8 | 0.4% | Sep 17, 2025 | A security vulnerability has been detected in itsourcecode Online Clinic Management System 1.0. Affected by this issue i... |
| CVE-2025-10617 | HIGH | 8.8 | 0.4% | Sep 17, 2025 | A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown... |
| CVE-2025-10616 | HIGH | 8.8 | 0.4% | Sep 17, 2025 | A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file ... |
| CVE-2025-59353 | HIGH | 7.5 | 0.2% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain... |
| CVE-2025-59348 | HIGH | 7.5 | 0.3% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceF... |
| CVE-2025-10615 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /adm... |
| CVE-2025-59416 | HIGH | 7.2 | 0.3% | Sep 17, 2025 | The Scratch Channel is a news website. If the user makes a fork, they can change the admins and make an article. Since t... |
| CVE-2025-10613 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown functi... |
| CVE-2025-10608 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file ... |
| CVE-2025-59341 | HIGH | 7.7 | 1.5% | Sep 17, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion... |
| CVE-2025-58432 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all ... |
| CVE-2025-35436 | HIGH | 7.5 | 0.5% | Sep 17, 2025 | CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote... |
| CVE-2025-35433 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now