2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58354 | MEDIUM | 6.9 | 0.3% | Sep 23, 2025 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2025-56311 | MEDIUM | 6.5 | 0.1% | Sep 23, 2025 | In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authentic... |
| CVE-2025-59825 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-... |
| CVE-2025-57636 | MEDIUM | 6.5 | 1.1% | Sep 23, 2025 | OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injecti... |
| CVE-2025-58674 | MEDIUM | 5.9 | 0.2% | Sep 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows S... |
| CVE-2025-56146 | MEDIUM | 5.3 | 0.2% | Sep 23, 2025 | Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity. |
| CVE-2025-45326 | MEDIUM | 6.5 | 0.3% | Sep 23, 2025 | An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.p... |
| CVE-2025-59821 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59548 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59547 | MEDIUM | 5.3 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59546 | MEDIUM | 4.8 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59539 | MEDIUM | 5.4 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-58246 | MEDIUM | 4.3 | 0.3% | Sep 23, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. Th... |
| CVE-2025-57639 | MEDIUM | 6.5 | 1.0% | Sep 23, 2025 | OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the ... |
| CVE-2025-29084 | MEDIUM | 6.5 | 0.4% | Sep 23, 2025 | SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu... |
| CVE-2025-29083 | MEDIUM | 6.5 | 0.4% | Sep 23, 2025 | SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu... |
| CVE-2025-0209 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due... |
| CVE-2025-56304 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page. |
| CVE-2025-0663 | MEDIUM | 6.8 | 0.2% | Sep 23, 2025 | A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Ada... |
| CVE-2025-57407 | MEDIUM | 5.4 | 0.2% | Sep 23, 2025 | A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticat... |
| CVE-2025-4760 | MEDIUM | 4.8 | 0.2% | Sep 23, 2025 | An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper valida... |
| CVE-2025-9342 | MEDIUM | 6.5 | 0.3% | Sep 23, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privile... |
| CVE-2025-7106 | MEDIUM | 5.3 | 0.3% | Sep 23, 2025 | danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `c... |
| CVE-2025-10548 | MEDIUM | 6.5 | 0.4% | Sep 23, 2025 | The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the insta... |
| CVE-2025-39887 | MEDIUM | 5.5 | 0.1% | Sep 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix null-ptr-deref in bitmap_parse... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now