2025 CVE Vulnerabilities
45,152 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59144 | HIGH | 8.8 | 0.4% | Sep 15, 2025 | debug is a JavaScript debugging utility. On 8 September 2025, the npm publishing account for debug was taken over after ... |
| CVE-2025-59143 | HIGH | 8.8 | 0.4% | Sep 15, 2025 | color is a Javascript color conversion and manipulation library. On 8 September 2025, the npm publishing account for col... |
| CVE-2025-59142 | HIGH | 8.8 | 0.4% | Sep 15, 2025 | color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-... |
| CVE-2025-59141 | HIGH | 8.8 | 0.4% | Sep 15, 2025 | simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken... |
| CVE-2025-59140 | HIGH | 8.8 | 0.4% | Sep 15, 2025 | backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken ... |
| CVE-2025-10472 | HIGH | 7.5 | 0.8% | Sep 15, 2025 | A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download... |
| CVE-2025-10471 | HIGH | 8.8 | 0.3% | Sep 15, 2025 | A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaCon... |
| CVE-2025-10203 | HIGH | 8.5 | 0.2% | Sep 15, 2025 | Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrar... |
| CVE-2025-57248 | HIGH | 7.3 | 0.2% | Sep 15, 2025 | A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu fil... |
| CVE-2025-43793 | HIGH | 7.5 | 0.4% | Sep 15, 2025 | Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202... |
| CVE-2025-10491 | HIGH | 7.8 | 0.1% | Sep 15, 2025 | The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker t... |
| CVE-2025-6202 | HIGH | 7.1 | 0.3% | Sep 15, 2025 | Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Inte... |
| CVE-2025-56710 | HIGH | 7.3 | 0.2% | Sep 15, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Ma... |
| CVE-2025-50944 | HIGH | 8.8 | 0.2% | Sep 15, 2025 | An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes ... |
| CVE-2025-50110 | HIGH | 8.8 | 0.2% | Sep 15, 2025 | An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, th... |
| CVE-2025-3025 | HIGH | 7.3 | 0.1% | Sep 15, 2025 | Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local use... |
| CVE-2025-39804 | HIGH | 7.8 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm64/poly1305: Fix register corruption... |
| CVE-2025-39803 | HIGH | 7.8 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove WARN_ON_ONCE() call from uf... |
| CVE-2025-39802 | HIGH | 7.8 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm/poly1305: Fix register corruption i... |
| CVE-2025-59358 | HIGH | 7.5 | 1.0% | Sep 15, 2025 | The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kuber... |
| CVE-2025-10443 | HIGH | 8.8 | 3.7% | Sep 15, 2025 | A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function fo... |
| CVE-2025-10442 | HIGH | 8.8 | 8.3% | Sep 15, 2025 | A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /... |
| CVE-2025-10431 | HIGH | 8.8 | 0.4% | Sep 15, 2025 | A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of t... |
| CVE-2025-10430 | HIGH | 8.8 | 0.4% | Sep 15, 2025 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown fun... |
| CVE-2025-10429 | HIGH | 8.8 | 0.4% | Sep 15, 2025 | A vulnerability was detected in SourceCodester Pet Grooming Management Software 1.0. Affected by this vulnerability is a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now