2025 CVE Vulnerabilities
45,327 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43796 | HIGH | 7.5 | 0.3% | Sep 12, 2025 | Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA... |
| CVE-2025-10325 | HIGH | 8.8 | 6.8% | Sep 12, 2025 | A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file... |
| CVE-2025-4235 | HIGH | 7.2 | 0.2% | Sep 12, 2025 | An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the ... |
| CVE-2025-57579 | HIGH | 8 | 0.6% | Sep 12, 2025 | An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code vi... |
| CVE-2025-57578 | HIGH | 8 | 0.4% | Sep 12, 2025 | An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password |
| CVE-2025-57577 | HIGH | 8 | 0.5% | Sep 12, 2025 | An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: t... |
| CVE-2025-39797 | HIGH | 7.8 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates ... |
| CVE-2025-39796 | HIGH | 7.8 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: lapbether: ignore ops-locked netdevs Syzkalle... |
| CVE-2025-39793 | HIGH | 7.8 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/memmap: cast nr_pages to size_t before shi... |
| CVE-2025-59054 | HIGH | 8.5 | 0.2% | Sep 12, 2025 | dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execu... |
| CVE-2025-10318 | HIGH | 8.8 | 0.4% | Sep 12, 2025 | A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of t... |
| CVE-2025-6638 | HIGH | 7.5 | 0.5% | Sep 12, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp... |
| CVE-2025-27240 | HIGH | 7.2 | 1.2% | Sep 12, 2025 | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visibl... |
| CVE-2025-27234 | HIGH | 7.3 | 0.3% | Sep 12, 2025 | Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex... |
| CVE-2025-10265 | HIGH | 8.8 | 1.1% | Sep 12, 2025 | Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote att... |
| CVE-2025-7448 | HIGH | 8.6 | 0.2% | Sep 12, 2025 | Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the ... |
| CVE-2025-9086 | HIGH | 7.5 | 1.4% | Sep 12, 2025 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak w... |
| CVE-2025-8575 | HIGH | 7.2 | 0.7% | Sep 12, 2025 | The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i... |
| CVE-2025-6454 | HIGH | 8.8 | 0.6% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18... |
| CVE-2025-2256 | HIGH | 7.5 | 0.5% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.... |
| CVE-2025-10291 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of th... |
| CVE-2025-10278 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/tr... |
| CVE-2025-10277 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file... |
| CVE-2025-10276 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown cod... |
| CVE-2025-10269 | HIGH | 7.5 | 0.5% | Sep 12, 2025 | The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now