2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57817 | HIGH | 7.2 | 0.4% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endp... |
| CVE-2025-57816 | HIGH | 7.5 | 0.4% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-bas... |
| CVE-2025-10106 | HIGH | 8.8 | 0.4% | Sep 8, 2025 | A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collec... |
| CVE-2025-52288 | HIGH | 7.5 | 0.4% | Sep 8, 2025 | Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Ma... |
| CVE-2025-10105 | HIGH | 8.8 | 0.3% | Sep 8, 2025 | A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the f... |
| CVE-2025-52389 | HIGH | 8.8 | 0.4% | Sep 8, 2025 | An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attacke... |
| CVE-2025-9112 | HIGH | 8.8 | 0.5% | Sep 8, 2025 | The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'do... |
| CVE-2025-55849 | HIGH | 8.4 | 0.2% | Sep 8, 2025 | WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee |
| CVE-2025-56265 | HIGH | 8.8 | 0.6% | Sep 8, 2025 | An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attac... |
| CVE-2025-10098 | HIGH | 8.8 | 0.4% | Sep 8, 2025 | A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the fil... |
| CVE-2025-59033 | HIGH | 7.4 | 0.2% | Sep 8, 2025 | The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries... |
| CVE-2025-56630 | HIGH | 7.3 | 0.2% | Sep 8, 2025 | FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Colum... |
| CVE-2025-55998 | HIGH | 8.1 | 0.3% | Sep 8, 2025 | A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacke... |
| CVE-2025-40930 | HIGH | 7.5 | 0.6% | Sep 8, 2025 | JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing craft... |
| CVE-2025-40928 | HIGH | 7.5 | 0.6% | Sep 8, 2025 | JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabl... |
| CVE-2025-36855 | HIGH | 8.8 | 0.7% | Sep 8, 2025 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. P... |
| CVE-2025-36854 | HIGH | 8.1 | 0.6% | Sep 8, 2025 | A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream whi... |
| CVE-2025-36853 | HIGH | 7.5 | 0.5% | Sep 8, 2025 | A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: ... |
| CVE-2025-10093 | HIGH | 7.5 | 0.9% | Sep 8, 2025 | A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi... |
| CVE-2025-41708 | HIGH | 7.4 | 0.2% | Sep 8, 2025 | Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacke... |
| CVE-2025-41682 | HIGH | 8.8 | 0.3% | Sep 8, 2025 | An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufactu... |
| CVE-2025-41664 | HIGH | 7.5 | 0.2% | Sep 8, 2025 | A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates... |
| CVE-2025-10087 | HIGH | 7.2 | 0.4% | Sep 8, 2025 | A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknow... |
| CVE-2025-8085 | HIGH | 8.6 | 16.4% | Sep 8, 2025 | The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoi... |
| CVE-2025-10085 | HIGH | 8.8 | 0.3% | Sep 8, 2025 | A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now