2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47695 | HIGH | 7.5 | 0.5% | Sep 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47694 | HIGH | 7.1 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Design... |
| CVE-2025-47579 | HIGH | 8.1 | 0.3% | Sep 9, 2025 | Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue... |
| CVE-2025-47571 | HIGH | 7.5 | 0.4% | Sep 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47570 | HIGH | 7.1 | 0.2% | Sep 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooComm... |
| CVE-2025-32689 | HIGH | 7.5 | 0.3% | Sep 9, 2025 | Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects ... |
| CVE-2025-9872 | HIGH | 8.8 | 13.5% | Sep 9, 2025 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe... |
| CVE-2025-9712 | HIGH | 8.8 | 20.5% | Sep 9, 2025 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe... |
| CVE-2025-55148 | HIGH | 7.6 | 0.5% | Sep 9, 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z... |
| CVE-2025-55147 | HIGH | 8.8 | 0.6% | Sep 9, 2025 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before... |
| CVE-2025-55145 | HIGH | 8.9 | 0.6% | Sep 9, 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z... |
| CVE-2025-55142 | HIGH | 8.8 | 0.9% | Sep 9, 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z... |
| CVE-2025-55141 | HIGH | 8.8 | 0.9% | Sep 9, 2025 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z... |
| CVE-2025-52915 | HIGH | 7.2 | 0.5% | Sep 9, 2025 | K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCT... |
| CVE-2025-52322 | HIGH | 7.5 | 0.5% | Sep 9, 2025 | An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session... |
| CVE-2025-9951 | HIGH | 7.2 | 0.4% | Sep 9, 2025 | A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execu... |
| CVE-2025-9364 | HIGH | 8.8 | 0.3% | Sep 9, 2025 | An open database issue exists in the affected product and version. The security issue stems from an over permissive Redi... |
| CVE-2025-9166 | HIGH | 7.5 | 0.4% | Sep 9, 2025 | A denial-of-service security issue exists in the affected product and version. The security issue stems from the control... |
| CVE-2025-9161 | HIGH | 8.8 | 0.5% | Sep 9, 2025 | A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the ... |
| CVE-2025-9160 | HIGH | 7 | 0.2% | Sep 9, 2025 | A code execution security issue exists in the affected product. An attacker with physical access could abuse the mainten... |
| CVE-2025-9065 | HIGH | 8.8 | 0.4% | Sep 9, 2025 | A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of ... |
| CVE-2025-7970 | HIGH | 7.5 | 0.3% | Sep 9, 2025 | A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within th... |
| CVE-2025-7350 | HIGH | 8.6 | 0.6% | Sep 9, 2025 | A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and 8000 devices. This can ... |
| CVE-2025-48208 | HIGH | 8.8 | 0.6% | Sep 9, 2025 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat .... |
| CVE-2025-24404 | HIGH | 8.8 | 0.5% | Sep 9, 2025 | XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now