2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50983 | HIGH | 8.3 | 0.3% | Aug 27, 2025 | SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4... |
| CVE-2025-53105 | HIGH | 7.5 | 0.3% | Aug 27, 2025 | GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that... |
| CVE-2025-9532 | HIGH | 8.8 | 0.4% | Aug 27, 2025 | A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/vi... |
| CVE-2025-9531 | HIGH | 8.8 | 0.4% | Aug 27, 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/a... |
| CVE-2025-9529 | HIGH | 7.2 | 0.5% | Aug 27, 2025 | A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include ... |
| CVE-2025-9528 | HIGH | 7.2 | 50.1% | Aug 27, 2025 | A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of th... |
| CVE-2025-9527 | HIGH | 8.8 | 1.3% | Aug 27, 2025 | A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup.... |
| CVE-2025-43882 | HIGH | 7.8 | 0.1% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged a... |
| CVE-2025-43730 | HIGH | 7.8 | 0.2% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ... |
| CVE-2025-43729 | HIGH | 7.8 | 0.1% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulner... |
| CVE-2025-9526 | HIGH | 8.8 | 1.3% | Aug 27, 2025 | A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the fil... |
| CVE-2025-9525 | HIGH | 8.8 | 1.3% | Aug 27, 2025 | A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /g... |
| CVE-2025-30064 | HIGH | 8.8 | 0.1% | Aug 27, 2025 | An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function chec... |
| CVE-2025-30038 | HIGH | 7.3 | 0.2% | Aug 27, 2025 | The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is expos... |
| CVE-2025-30037 | HIGH | 8.8 | 0.2% | Aug 27, 2025 | The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal s... |
| CVE-2025-30036 | HIGH | 8.8 | 0.1% | Aug 27, 2025 | Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the... |
| CVE-2025-57846 | HIGH | 8.5 | 0.1% | Aug 27, 2025 | Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a loc... |
| CVE-2025-57797 | HIGH | 8.5 | 0.1% | Aug 27, 2025 | Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6.5L61. If this vu... |
| CVE-2025-57820 | HIGH | 7.9 | 0.3% | Aug 26, 2025 | Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object ... |
| CVE-2025-35114 | HIGH | 8.7 | 0.3% | Aug 26, 2025 | Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The p... |
| CVE-2025-35113 | HIGH | 7.2 | 0.4% | Aug 26, 2025 | Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticat... |
| CVE-2025-22412 | HIGH | 8.8 | 0.2% | Aug 26, 2025 | In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could ... |
| CVE-2025-22411 | HIGH | 8.8 | 0.2% | Aug 26, 2025 | In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. Th... |
| CVE-2025-22410 | HIGH | 8.4 | 0.1% | Aug 26, 2025 | In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc... |
| CVE-2025-22409 | HIGH | 8.4 | 0.1% | Aug 26, 2025 | In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now