2025 CVE Vulnerabilities
45,155 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52494 | HIGH | 7.5 | 0.3% | Sep 3, 2025 | Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling o... |
| CVE-2025-45805 | HIGH | 7.6 | 0.4% | Sep 3, 2025 | In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript cod... |
| CVE-2025-20336 | HIGH | 7.5 | 0.3% | Sep 3, 2025 | A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C... |
| CVE-2025-20326 | HIGH | 8.8 | 0.2% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and ... |
| CVE-2025-20287 | HIGH | 8.8 | 0.3% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a... |
| CVE-2025-9959 | HIGH | 7.6 | 0.3% | Sep 3, 2025 | Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sand... |
| CVE-2025-9866 | HIGH | 8.8 | 0.4% | Sep 3, 2025 | Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass c... |
| CVE-2025-9920 | HIGH | 7.2 | 0.4% | Sep 3, 2025 | A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of... |
| CVE-2025-55852 | HIGH | 7.5 | 0.4% | Sep 3, 2025 | Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or s... |
| CVE-2025-0280 | HIGH | 7.5 | 0.1% | Sep 3, 2025 | A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access. |
| CVE-2025-58644 | HIGH | 7.2 | 0.4% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes... |
| CVE-2025-58643 | HIGH | 7.2 | 0.4% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-q... |
| CVE-2025-58642 | HIGH | 7.2 | 0.4% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition ltl-freight... |
| CVE-2025-58637 | HIGH | 7.5 | 0.4% | Sep 3, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58608 | HIGH | 7.5 | 0.4% | Sep 3, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-58604 | HIGH | 7.6 | 0.3% | Sep 3, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Min... |
| CVE-2025-57151 | HIGH | 8.8 | 0.6% | Sep 3, 2025 | phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the ... |
| CVE-2025-57150 | HIGH | 7.2 | 0.6% | Sep 3, 2025 | phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php v... |
| CVE-2025-57147 | HIGH | 7.5 | 0.5% | Sep 3, 2025 | A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack ... |
| CVE-2025-57146 | HIGH | 8.1 | 0.4% | Sep 3, 2025 | phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobi... |
| CVE-2025-47421 | HIGH | 8.6 | 0.3% | Sep 3, 2025 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREEN... |
| CVE-2025-2416 | HIGH | 8.6 | 0.3% | Sep 3, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypa... |
| CVE-2025-26210 | HIGH | 8.8 | 0.5% | Sep 3, 2025 | DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepsee... |
| CVE-2025-53694 | HIGH | 7.5 | 5.3% | Sep 3, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), S... |
| CVE-2025-53691 | HIGH | 8.8 | 1.4% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now