2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39890 | MEDIUM | 5.5 | 0.1% | Sep 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_rea... |
| CVE-2025-39889 | MEDIUM | 5.5 | 0.1% | Sep 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on inco... |
| CVE-2025-58457 | MEDIUM | 4.3 | 0.3% | Sep 24, 2025 | Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insu... |
| CVE-2025-9031 | MEDIUM | 4.3 | 0.2% | Sep 24, 2025 | Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Doma... |
| CVE-2025-41716 | MEDIUM | 5.3 | 0.4% | Sep 24, 2025 | The web application allows an unauthenticated remote attacker to learn information about existing user accounts with the... |
| CVE-2025-48459 | MEDIUM | 5.3 | 0.5% | Sep 24, 2025 | Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0... |
| CVE-2025-43819 | MEDIUM | 6.5 | 0.2% | Sep 24, 2025 | A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.... |
| CVE-2025-43779 | MEDIUM | 6.1 | 0.2% | Sep 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024... |
| CVE-2025-58069 | MEDIUM | 6.9 | 0.2% | Sep 23, 2025 | The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerabili... |
| CVE-2025-54855 | MEDIUM | 4.2 | 0.1% | Sep 23, 2025 | Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability... |
| CVE-2025-58354 | MEDIUM | 6.9 | 0.3% | Sep 23, 2025 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2025-56311 | MEDIUM | 6.5 | 0.1% | Sep 23, 2025 | In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authentic... |
| CVE-2025-59825 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-... |
| CVE-2025-57636 | MEDIUM | 6.5 | 1.1% | Sep 23, 2025 | OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injecti... |
| CVE-2025-58674 | MEDIUM | 5.9 | 0.2% | Sep 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows S... |
| CVE-2025-56146 | MEDIUM | 5.3 | 0.2% | Sep 23, 2025 | Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity. |
| CVE-2025-45326 | MEDIUM | 6.5 | 0.3% | Sep 23, 2025 | An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.p... |
| CVE-2025-59821 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59548 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59547 | MEDIUM | 5.3 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59546 | MEDIUM | 4.8 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59539 | MEDIUM | 5.4 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-58246 | MEDIUM | 4.3 | 0.3% | Sep 23, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. Th... |
| CVE-2025-57639 | MEDIUM | 6.5 | 1.0% | Sep 23, 2025 | OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the ... |
| CVE-2025-29084 | MEDIUM | 6.5 | 0.4% | Sep 23, 2025 | SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now