2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10947 | MEDIUM | 5.5 | 0.4% | Sep 25, 2025 | A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of... |
| CVE-2025-10946 | MEDIUM | 5.1 | 0.2% | Sep 25, 2025 | A vulnerability was detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. The affected element is a... |
| CVE-2025-10945 | MEDIUM | 5.1 | 0.2% | Sep 25, 2025 | A security vulnerability has been detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. Impacted is... |
| CVE-2025-10944 | MEDIUM | 5.1 | 0.2% | Sep 25, 2025 | A weakness has been identified in yi-ge get-header-ip up to 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15. This issue affects... |
| CVE-2025-10943 | MEDIUM | 5.1 | 0.2% | Sep 25, 2025 | A security flaw has been discovered in MikeCen WeChat-Face-Recognition up to 6e3f72bf8547d80b59e330f1137e4aa505f492c1. T... |
| CVE-2025-10940 | MEDIUM | 4.8 | 0.2% | Sep 25, 2025 | A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file... |
| CVE-2025-21056 | MEDIUM | 6.6 | 0.2% | Sep 25, 2025 | Improper input validation in Retail Mode prior to version 5.59.4 allows self attackers to execute privileged commands on... |
| CVE-2025-57324 | MEDIUM | 6.5 | 0.3% | Sep 24, 2025 | parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateContr... |
| CVE-2025-57320 | MEDIUM | 6.5 | 0.3% | Sep 24, 2025 | json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setDa... |
| CVE-2025-59824 | MEDIUM | 5.4 | 0.2% | Sep 24, 2025 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLi... |
| CVE-2025-59525 | MEDIUM | 6.1 | 0.3% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization... |
| CVE-2025-57351 | MEDIUM | 6.5 | 0.4% | Sep 24, 2025 | A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation... |
| CVE-2025-57348 | MEDIUM | 6.5 | 0.4% | Sep 24, 2025 | The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initializatio... |
| CVE-2025-55178 | MEDIUM | 5.3 | 0.5% | Sep 24, 2025 | Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could pote... |
| CVE-2025-59524 | MEDIUM | 6.1 | 0.3% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow ... |
| CVE-2025-57354 | MEDIUM | 6.5 | 0.5% | Sep 24, 2025 | A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user... |
| CVE-2025-57353 | MEDIUM | 5.3 | 0.3% | Sep 24, 2025 | The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Du... |
| CVE-2025-57352 | MEDIUM | 5.3 | 0.3% | Sep 24, 2025 | A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespa... |
| CVE-2025-48867 | MEDIUM | 4.8 | 0.2% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerabi... |
| CVE-2025-20338 | MEDIUM | 6.7 | 0.1% | Sep 24, 2025 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri... |
| CVE-2025-20316 | MEDIUM | 5.3 | 0.3% | Sep 24, 2025 | A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X... |
| CVE-2025-20314 | MEDIUM | 6.7 | 0.1% | Sep 24, 2025 | A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an una... |
| CVE-2025-20313 | MEDIUM | 6.7 | 0.2% | Sep 24, 2025 | Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileg... |
| CVE-2025-20293 | MEDIUM | 5.3 | 0.2% | Sep 24, 2025 | A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for ... |
| CVE-2025-20240 | MEDIUM | 6.1 | 0.3% | Sep 24, 2025 | A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attack... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now