2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59017 | HIGH | 8.8 | 0.3% | Sep 9, 2025 | Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, ... |
| CVE-2025-41701 | HIGH | 7.8 | 0.2% | Sep 9, 2025 | An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulat... |
| CVE-2025-40798 | HIGH | 8.7 | 0.5% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
| CVE-2025-40797 | HIGH | 8.7 | 0.5% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
| CVE-2025-40796 | HIGH | 8.7 | 0.4% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
| CVE-2025-9539 | HIGH | 8 | 0.4% | Sep 9, 2025 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP... |
| CVE-2025-10122 | HIGH | 7.2 | 0.3% | Sep 9, 2025 | A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/control... |
| CVE-2025-42933 | HIGH | 8.8 | 0.3% | Sep 9, 2025 | When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of ce... |
| CVE-2025-42929 | HIGH | 8.1 | 0.2% | Sep 9, 2025 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbi... |
| CVE-2025-42916 | HIGH | 8.1 | 0.2% | Sep 9, 2025 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbi... |
| CVE-2025-10120 | HIGH | 8.8 | 0.8% | Sep 9, 2025 | A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /g... |
| CVE-2025-10116 | HIGH | 7.3 | 0.4% | Sep 9, 2025 | A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admi... |
| CVE-2025-10115 | HIGH | 7.3 | 0.3% | Sep 9, 2025 | A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php.... |
| CVE-2025-58757 | HIGH | 8.8 | 0.6% | Sep 9, 2025 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the... |
| CVE-2025-58756 | HIGH | 8.8 | 0.7% | Sep 9, 2025 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in ... |
| CVE-2025-58755 | HIGH | 8.8 | 0.6% | Sep 9, 2025 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extracta... |
| CVE-2025-58745 | HIGH | 8.8 | 0.7% | Sep 8, 2025 | WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary... |
| CVE-2025-58454 | HIGH | 8.2 | 0.3% | Sep 8, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1... |
| CVE-2025-58453 | HIGH | 8.2 | 0.3% | Sep 8, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1... |
| CVE-2025-1761 | HIGH | 7.5 | 0.3% | Sep 8, 2025 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me... |
| CVE-2025-10110 | HIGH | 8.8 | 0.3% | Sep 8, 2025 | A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipul... |
| CVE-2025-58451 | HIGH | 8.7 | 0.3% | Sep 8, 2025 | Cattown is a JavaScript markdown parser. Versions prior to 1.0.2 used regular expressions with inefficient, potentially ... |
| CVE-2025-58449 | HIGH | 8.7 | 0.3% | Sep 8, 2025 | Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to t... |
| CVE-2025-58444 | HIGH | 8.6 | 0.6% | Sep 8, 2025 | The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported i... |
| CVE-2025-58365 | HIGH | 8.7 | 0.5% | Sep 8, 2025 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Prior to version 9.14, th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now