2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36099 | MEDIUM | 4.9 | 0.3% | Sep 29, 2025 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted... |
| CVE-2025-57197 | MEDIUM | 6 | 0.2% | Sep 29, 2025 | In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for ... |
| CVE-2025-56807 | MEDIUM | 6.1 | 0.2% | Sep 29, 2025 | A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrat... |
| CVE-2025-43400 | MEDIUM | 6.3 | 6.5% | Sep 29, 2025 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 1... |
| CVE-2025-61659 | MEDIUM | 6.8 | 0.1% | Sep 29, 2025 | bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name. |
| CVE-2025-41245 | MEDIUM | 4.9 | 0.6% | Sep 29, 2025 | VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privi... |
| CVE-2025-11155 | MEDIUM | 6.8 | 0.2% | Sep 29, 2025 | The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is n... |
| CVE-2025-36352 | MEDIUM | 5.4 | 0.2% | Sep 29, 2025 | IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an ... |
| CVE-2025-36351 | MEDIUM | 4.3 | 0.2% | Sep 29, 2025 | IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST A... |
| CVE-2025-57428 | MEDIUM | 6.5 | 0.2% | Sep 29, 2025 | Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain... |
| CVE-2025-11147 | MEDIUM | 5.4 | 0.2% | Sep 29, 2025 | Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be exe... |
| CVE-2025-11146 | MEDIUM | 5.4 | 0.2% | Sep 29, 2025 | Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious ... |
| CVE-2025-10346 | MEDIUM | 6.1 | 0.2% | Sep 29, 2025 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validatio... |
| CVE-2025-10345 | MEDIUM | 6.1 | 0.2% | Sep 29, 2025 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validatio... |
| CVE-2025-10344 | MEDIUM | 6.1 | 0.2% | Sep 29, 2025 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validatio... |
| CVE-2025-10343 | MEDIUM | 6.1 | 0.2% | Sep 29, 2025 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validatio... |
| CVE-2025-10342 | MEDIUM | 6.1 | 0.2% | Sep 29, 2025 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validatio... |
| CVE-2025-10341 | MEDIUM | 6.1 | 0.2% | Sep 29, 2025 | HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validatio... |
| CVE-2025-11141 | MEDIUM | 4.7 | 3.9% | Sep 29, 2025 | A security flaw has been discovered in Ruijie NBR2100G-E up to 20250919. Affected by this issue is the function listActi... |
| CVE-2025-10504 | MEDIUM | 6.9 | 0.2% | Sep 29, 2025 | Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33. |
| CVE-2025-9904 | MEDIUM | 6.9 | 0.4% | Sep 29, 2025 | Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Pr... |
| CVE-2025-9903 | MEDIUM | 5.9 | 0.3% | Sep 29, 2025 | Out-of-bounds write vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printe... |
| CVE-2025-7698 | MEDIUM | 5.9 | 0.3% | Sep 29, 2025 | Out-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer... |
| CVE-2025-11125 | MEDIUM | 4.3 | 0.3% | Sep 29, 2025 | A vulnerability was found in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. Affected b... |
| CVE-2025-11124 | MEDIUM | 5.4 | 0.3% | Sep 28, 2025 | A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the fi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now