2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10214 | HIGH | 7.8 | 0.2% | Sep 10, 2025 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc... |
| CVE-2025-10213 | HIGH | 7.8 | 0.2% | Sep 10, 2025 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc... |
| CVE-2025-36759 | HIGH | 8.7 | 0.3% | Sep 10, 2025 | Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive informa... |
| CVE-2025-7049 | HIGH | 8.8 | 0.3% | Sep 10, 2025 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions u... |
| CVE-2025-41714 | HIGH | 8.8 | 0.6% | Sep 10, 2025 | The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an ... |
| CVE-2025-10049 | HIGH | 7.2 | 0.5% | Sep 10, 2025 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ... |
| CVE-2025-10040 | HIGH | 7.7 | 0.3% | Sep 10, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of dat... |
| CVE-2025-10001 | HIGH | 7.2 | 0.5% | Sep 10, 2025 | The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to m... |
| CVE-2025-59042 | HIGH | 7 | 0.1% | Sep 9, 2025 | PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being ap... |
| CVE-2025-59038 | HIGH | 8.6 | 0.3% | Sep 9, 2025 | Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9... |
| CVE-2025-10172 | HIGH | 8.8 | 1.0% | Sep 9, 2025 | A flaw has been found in UTT 750W up to 3.2.2-191225. This issue affects some unknown processing of the file /goform/for... |
| CVE-2025-54260 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | Substance3D - Modeler versions 1.22.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cra... |
| CVE-2025-54259 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | Substance3D - Modeler versions 1.22.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that c... |
| CVE-2025-54258 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | Substance3D - Modeler versions 1.22.2 and earlier are affected by a Use After Free vulnerability that could result in ar... |
| CVE-2025-49461 | HIGH | 7.4 | 0.3% | Sep 9, 2025 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service ... |
| CVE-2025-49460 | HIGH | 7.5 | 0.3% | Sep 9, 2025 | Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denia... |
| CVE-2025-49459 | HIGH | 7.8 | 0.1% | Sep 9, 2025 | Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0 may allow an authentic... |
| CVE-2025-10171 | HIGH | 8.8 | 1.0% | Sep 9, 2025 | A vulnerability was detected in UTT 1250GW up to 3.2.2-200710. This vulnerability affects the function sub_453DC of the ... |
| CVE-2025-59037 | HIGH | 8.6 | 0.3% | Sep 9, 2025 | DuckDB is an analytical in-process SQL database management system. On 08 September 2025, the DuckDB distribution for Nod... |
| CVE-2025-58765 | HIGH | 7.1 | 0.2% | Sep 9, 2025 | wabac.js provides a full web archive replay system, or 'wayback machine', using Service Workers. A Reflected Cross-Site ... |
| CVE-2025-58763 | HIGH | 7.2 | 1.7% | Sep 9, 2025 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Taut... |
| CVE-2025-54245 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-54244 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | Substance3D - Viewer versions 0.25.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r... |
| CVE-2025-54243 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | Substance3D - Viewer versions 0.25.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2025-54084 | HIGH | 8.5 | 0.8% | Sep 9, 2025 | OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now