2025 CVE Vulnerabilities
45,152 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-35432 | HIGH | 7.5 | 0.5% | Sep 17, 2025 | CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker... |
| CVE-2025-10602 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknow... |
| CVE-2025-40933 | HIGH | 7.5 | 0.4% | Sep 17, 2025 | Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an... |
| CVE-2025-10595 | HIGH | 8.8 | 0.4% | Sep 17, 2025 | A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is so... |
| CVE-2025-10205 | HIGH | 8.8 | 0.2% | Sep 17, 2025 | Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and ... |
| CVE-2025-10594 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an ... |
| CVE-2025-10593 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio... |
| CVE-2025-10592 | HIGH | 8.8 | 0.4% | Sep 17, 2025 | A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknow... |
| CVE-2025-8411 | HIGH | 7.1 | 0.2% | Sep 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft T... |
| CVE-2025-10157 | HIGH | 7.8 | 0.8% | Sep 17, 2025 | A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remot... |
| CVE-2025-10155 | HIGH | 7.8 | 0.8% | Sep 17, 2025 | An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0... |
| CVE-2025-59457 | HIGH | 7.7 | 0.8% | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows |
| CVE-2025-9450 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release... |
| CVE-2025-9449 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS De... |
| CVE-2025-9447 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWOR... |
| CVE-2025-9216 | HIGH | 8.8 | 0.8% | Sep 17, 2025 | The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor... |
| CVE-2025-10058 | HIGH | 8.1 | 0.6% | Sep 17, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion du... |
| CVE-2025-10057 | HIGH | 8.8 | 0.7% | Sep 17, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in a... |
| CVE-2025-10042 | HIGH | 7.5 | 0.9% | Sep 17, 2025 | The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and inc... |
| CVE-2025-59518 | HIGH | 8 | 1.2% | Sep 17, 2025 | In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It ... |
| CVE-2025-59307 | HIGH | 8.4 | 0.2% | Sep 17, 2025 | RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the wri... |
| CVE-2025-58116 | HIGH | 8.6 | 1.1% | Sep 17, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and... |
| CVE-2025-10589 | HIGH | 8.8 | 1.0% | Sep 17, 2025 | The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenti... |
| CVE-2025-10143 | HIGH | 7.5 | 0.6% | Sep 17, 2025 | The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0... |
| CVE-2025-37127 | HIGH | 7.2 | 0.1% | Sep 16, 2025 | A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now