2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58358 | HIGH | 7.5 | 1.0% | Sep 4, 2025 | Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain ... |
| CVE-2025-58355 | HIGH | 7.7 | 0.3% | Sep 4, 2025 | Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or over... |
| CVE-2025-58057 | HIGH | 7.5 | 0.6% | Sep 4, 2025 | Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan... |
| CVE-2025-43772 | HIGH | 7.1 | 0.5% | Sep 4, 2025 | Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older u... |
| CVE-2025-36907 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer ove... |
| CVE-2025-36906 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer ov... |
| CVE-2025-36905 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This ... |
| CVE-2025-36903 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local e... |
| CVE-2025-36901 | HIGH | 8.8 | 0.1% | Sep 4, 2025 | WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223. |
| CVE-2025-36899 | HIGH | 8.4 | 0.1% | Sep 4, 2025 | There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to ph... |
| CVE-2025-36898 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of pri... |
| CVE-2025-36895 | HIGH | 7.5 | 0.2% | Sep 4, 2025 | Information disclosure |
| CVE-2025-36894 | HIGH | 7.5 | 0.3% | Sep 4, 2025 | In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no ... |
| CVE-2025-36892 | HIGH | 7.5 | 0.2% | Sep 4, 2025 | Denial of service |
| CVE-2025-36891 | HIGH | 8.8 | 0.2% | Sep 4, 2025 | Elevation of privilege |
| CVE-2025-36887 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrec... |
| CVE-2025-2417 | HIGH | 8.6 | 0.4% | Sep 4, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication By... |
| CVE-2025-2411 | HIGH | 8.6 | 0.4% | Sep 4, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypas... |
| CVE-2025-58056 | HIGH | 7.5 | 0.6% | Sep 3, 2025 | Netty is an asynchronous event-driven network application framework for development of maintainable high performance pro... |
| CVE-2025-57833 | HIGH | 8.1 | 15.6% | Sep 3, 2025 | An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subjec... |
| CVE-2025-55748 | HIGH | 7.5 | 1.6% | Sep 3, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2... |
| CVE-2025-9365 | HIGH | 8.4 | 0.2% | Sep 3, 2025 | Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a speci... |
| CVE-2025-55162 | HIGH | 8.8 | 0.3% | Sep 3, 2025 | Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In vers... |
| CVE-2025-56803 | HIGH | 8.4 | 1.1% | Sep 3, 2025 | Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An atta... |
| CVE-2025-52494 | HIGH | 7.5 | 0.3% | Sep 3, 2025 | Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now