2025 CVE Vulnerabilities
45,328 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39738 | HIGH | 7.8 | 0.2% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped... |
| CVE-2025-58145 | HIGH | 7.5 | 0.3% | Sep 11, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-58144 | HIGH | 7.5 | 0.4% | Sep 11, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-10193 | HIGH | 7.4 | 0.2% | Sep 11, 2025 | DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protection... |
| CVE-2025-9018 | HIGH | 8.8 | 0.3% | Sep 11, 2025 | The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capab... |
| CVE-2025-58320 | HIGH | 7.3 | 13.1% | Sep 11, 2025 | Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability. |
| CVE-2025-48041 | HIGH | 7.1 | 0.4% | Sep 11, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive... |
| CVE-2025-9918 | HIGH | 8.7 | 0.6% | Sep 11, 2025 | A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.... |
| CVE-2025-9874 | HIGH | 7.5 | 0.6% | Sep 11, 2025 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i... |
| CVE-2025-9693 | HIGH | 8 | 0.5% | Sep 11, 2025 | The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file del... |
| CVE-2025-9073 | HIGH | 7.5 | 0.4% | Sep 11, 2025 | The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions ... |
| CVE-2025-8425 | HIGH | 8.8 | 0.3% | Sep 11, 2025 | The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e... |
| CVE-2025-8422 | HIGH | 7.5 | 0.6% | Sep 11, 2025 | The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all ver... |
| CVE-2025-8417 | HIGH | 8.1 | 0.7% | Sep 11, 2025 | The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, ... |
| CVE-2025-9059 | HIGH | 8.8 | 0.1% | Sep 11, 2025 | The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hij... |
| CVE-2025-10236 | HIGH | 7.5 | 0.7% | Sep 11, 2025 | A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the... |
| CVE-2025-59052 | HIGH | 7.1 | 0.3% | Sep 10, 2025 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2025-54376 | HIGH | 7.5 | 0.7% | Sep 10, 2025 | Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v... |
| CVE-2025-59049 | HIGH | 7.5 | 1.7% | Sep 10, 2025 | Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file servi... |
| CVE-2025-10210 | HIGH | 8.8 | 1.3% | Sep 10, 2025 | A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modu... |
| CVE-2025-10201 | HIGH | 8.8 | 0.3% | Sep 10, 2025 | Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remo... |
| CVE-2025-10200 | HIGH | 8.8 | 0.6% | Sep 10, 2025 | Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potenti... |
| CVE-2025-8696 | HIGH | 7.5 | 0.4% | Sep 10, 2025 | If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for t... |
| CVE-2025-57392 | HIGH | 7.8 | 0.2% | Sep 10, 2025 | BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone... |
| CVE-2025-55976 | HIGH | 8.4 | 3.0% | Sep 10, 2025 | Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated us... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now