2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14871 | HIGH | 7.5 | — | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and... |
| CVE-2025-11395 | MEDIUM | 5.5 | — | Sep 15, 2026 | A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create ... |
| CVE-2025-66974 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attacke... |
| CVE-2025-5802 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of use... |
| CVE-2025-13166 | LOW | 3.7 | 0.2% | Sep 15, 2026 | The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered us... |
| CVE-2025-24890 | MEDIUM | 6.8 | 0.2% | Sep 14, 2026 | gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats r... |
| CVE-2025-26790 | LOW | 3.7 | 0.3% | Sep 14, 2026 | Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memo... |
| CVE-2025-68624 | MEDIUM | 4.3 | 0.3% | Sep 14, 2026 | N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user ... |
| CVE-2025-64031 | LOW | 2.5 | 0.1% | Sep 14, 2026 | libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field... |
| CVE-2025-63842 | MEDIUM | 5.4 | 0.2% | Sep 14, 2026 | A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote ... |
| CVE-2025-70820 | LOW | 3.5 | 0.2% | Sep 13, 2026 | Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder. |
| CVE-2025-70819 | MEDIUM | 6.3 | 0.1% | Sep 13, 2026 | Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as ... |
| CVE-2025-64059 | LOW | 1.8 | 0.2% | Sep 13, 2026 | Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is ... |
| CVE-2025-45480 | LOW | 3 | 0.2% | Sep 13, 2026 | Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary. |
| CVE-2025-69904 | MEDIUM | 4.9 | 0.4% | Sep 11, 2026 | Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on t... |
| CVE-2025-15679 | HIGH | 7.3 | 0.1% | Sep 11, 2026 | Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a pa... |
| CVE-2025-15695 | LOW | 3.5 | 0.2% | Sep 11, 2026 | The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the ... |
| CVE-2025-57231 | HIGH | 7.5 | 1.3% | Sep 10, 2026 | Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local file... |
| CVE-2025-51619 | MEDIUM | 5.5 | — | Sep 9, 2026 | A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause... |
| CVE-2025-71418 | MEDIUM | 5.3 | — | Sep 9, 2026 | PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients ... |
| CVE-2025-71417 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_P... |
| CVE-2025-3271 | MEDIUM | 4.8 | 0.3% | Sep 9, 2026 | Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS |
| CVE-2025-46808 | MEDIUM | 6.8 | 0.2% | Sep 9, 2026 | An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive informatio... |
| CVE-2025-7062 | MEDIUM | 5.2 | 0.3% | Sep 9, 2026 | A stored cross-site scripting (XSS) vulnerability has been identified in the H5P module `h5p-nodejs-library` by Lumi Edu... |
| CVE-2025-15690 | MEDIUM | 6.8 | 0.2% | Sep 9, 2026 | The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post bef... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now