2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10200 | HIGH | 8.8 | 0.6% | Sep 10, 2025 | Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potenti... |
| CVE-2025-8696 | HIGH | 7.5 | 0.4% | Sep 10, 2025 | If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for t... |
| CVE-2025-57392 | HIGH | 7.8 | 0.2% | Sep 10, 2025 | BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone... |
| CVE-2025-55976 | HIGH | 8.4 | 3.0% | Sep 10, 2025 | Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated us... |
| CVE-2025-50892 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges f... |
| CVE-2025-57642 | HIGH | 7.2 | 1.5% | Sep 10, 2025 | A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she... |
| CVE-2025-59045 | HIGH | 7.1 | 0.3% | Sep 10, 2025 | Stalwart is a mail and collaboration server. Starting in version 0.12.0 and prior to version 0.13.3, a memory exhaustion... |
| CVE-2025-43888 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information in... |
| CVE-2025-43887 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerab... |
| CVE-2025-43885 | HIGH | 7.8 | 0.5% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Ele... |
| CVE-2025-43725 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default P... |
| CVE-2025-20340 | HIGH | 7.4 | 0.6% | Sep 10, 2025 | A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthen... |
| CVE-2025-56466 | HIGH | 7.5 | 0.3% | Sep 10, 2025 | Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information. |
| CVE-2025-56413 | HIGH | 8.8 | 1.2% | Sep 10, 2025 | OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary comman... |
| CVE-2025-56407 | HIGH | 8.8 | 0.3% | Sep 10, 2025 | A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function ... |
| CVE-2025-56406 | HIGH | 7.5 | 0.4% | Sep 10, 2025 | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary comma... |
| CVE-2025-56405 | HIGH | 7.5 | 0.3% | Sep 10, 2025 | An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the ... |
| CVE-2025-56404 | HIGH | 7.5 | 0.3% | Sep 10, 2025 | An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the... |
| CVE-2025-10231 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstanc... |
| CVE-2025-7718 | HIGH | 8.8 | 0.3% | Sep 10, 2025 | The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation ... |
| CVE-2025-10225 | HIGH | 8.7 | 0.4% | Sep 10, 2025 | Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in... |
| CVE-2025-10224 | HIGH | 7.1 | 0.3% | Sep 10, 2025 | Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on... |
| CVE-2025-10223 | HIGH | 8.1 | 0.2% | Sep 10, 2025 | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windo... |
| CVE-2025-40979 | HIGH | 7 | 0.1% | Sep 10, 2025 | DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this... |
| CVE-2025-10215 | HIGH | 7.8 | 0.2% | Sep 10, 2025 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now