2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10176 | HIGH | 7.2 | 0.7% | Sep 12, 2025 | The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici... |
| CVE-2025-45587 | HIGH | 7 | 0.2% | Sep 12, 2025 | A stack overflow in the FTP service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to cause a Denial of... |
| CVE-2025-45586 | HIGH | 7.5 | 0.3% | Sep 12, 2025 | An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a ... |
| CVE-2025-45584 | HIGH | 7.5 | 0.4% | Sep 12, 2025 | Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download ... |
| CVE-2025-43796 | HIGH | 7.5 | 0.3% | Sep 12, 2025 | Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA... |
| CVE-2025-10325 | HIGH | 8.8 | 6.8% | Sep 12, 2025 | A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file... |
| CVE-2025-4235 | HIGH | 7.2 | 0.2% | Sep 12, 2025 | An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the ... |
| CVE-2025-57579 | HIGH | 8 | 0.6% | Sep 12, 2025 | An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code vi... |
| CVE-2025-57578 | HIGH | 8 | 0.4% | Sep 12, 2025 | An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password |
| CVE-2025-57577 | HIGH | 8 | 0.5% | Sep 12, 2025 | An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: t... |
| CVE-2025-39797 | HIGH | 7.8 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates ... |
| CVE-2025-39796 | HIGH | 7.8 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: lapbether: ignore ops-locked netdevs Syzkalle... |
| CVE-2025-39793 | HIGH | 7.8 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/memmap: cast nr_pages to size_t before shi... |
| CVE-2025-59054 | HIGH | 8.5 | 0.2% | Sep 12, 2025 | dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execu... |
| CVE-2025-10318 | HIGH | 8.8 | 0.4% | Sep 12, 2025 | A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of t... |
| CVE-2025-6638 | HIGH | 7.5 | 0.5% | Sep 12, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp... |
| CVE-2025-27240 | HIGH | 7.2 | 1.2% | Sep 12, 2025 | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visibl... |
| CVE-2025-27234 | HIGH | 7.3 | 0.3% | Sep 12, 2025 | Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex... |
| CVE-2025-10265 | HIGH | 8.8 | 1.1% | Sep 12, 2025 | Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote att... |
| CVE-2025-7448 | HIGH | 8.6 | 0.2% | Sep 12, 2025 | Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the ... |
| CVE-2025-9086 | HIGH | 7.5 | 1.3% | Sep 12, 2025 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak... |
| CVE-2025-8575 | HIGH | 7.2 | 0.7% | Sep 12, 2025 | The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i... |
| CVE-2025-6454 | HIGH | 8.8 | 0.6% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18... |
| CVE-2025-2256 | HIGH | 7.5 | 0.5% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.... |
| CVE-2025-10291 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now