2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59797 | MEDIUM | 5.8 | 0.3% | Sep 22, 2025 | Profession Fit 5.0.99 Build 44910 allows authorization bypass via a direct request for /api/challenges/{id} and also URL... |
| CVE-2025-46711 | MEDIUM | 5.5 | 0.1% | Sep 22, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger NULL pointer derefe... |
| CVE-2025-10794 | MEDIUM | 6.1 | 0.4% | Sep 22, 2025 | A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the ... |
| CVE-2025-9035 | MEDIUM | 5.4 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Horato Inte... |
| CVE-2025-25177 | MEDIUM | 5.1 | 0.1% | Sep 22, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern... |
| CVE-2025-8079 | MEDIUM | 4.6 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akıllı Tica... |
| CVE-2025-0875 | MEDIUM | 6.5 | 0.4% | Sep 22, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. C... |
| CVE-2025-10787 | MEDIUM | 6.3 | 0.2% | Sep 22, 2025 | A vulnerability was found in MuYuCMS up to 2.7. Impacted is an unknown function of the file /index/index.html of the com... |
| CVE-2025-9541 | MEDIUM | 4.7 | 0.2% | Sep 22, 2025 | The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the ... |
| CVE-2025-9540 | MEDIUM | 4.7 | 0.2% | Sep 22, 2025 | The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the ... |
| CVE-2025-9487 | MEDIUM | 4.7 | 0.2% | Sep 22, 2025 | The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc... |
| CVE-2025-9115 | MEDIUM | 5.6 | 0.2% | Sep 22, 2025 | The Etsy Shop WordPress plugin before 3.0.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it b... |
| CVE-2025-59801 | MEDIUM | 4.3 | 0.2% | Sep 22, 2025 | In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because th... |
| CVE-2025-59800 | MEDIUM | 5.5 | 0.2% | Sep 22, 2025 | In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a h... |
| CVE-2025-59799 | MEDIUM | 5.5 | 0.2% | Sep 22, 2025 | Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.... |
| CVE-2025-59798 | MEDIUM | 5.5 | 0.2% | Sep 22, 2025 | Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c. |
| CVE-2025-10777 | MEDIUM | 6.3 | 0.4% | Sep 22, 2025 | A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown function of the file /d... |
| CVE-2025-10774 | MEDIUM | 4.7 | 4.1% | Sep 22, 2025 | A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown part of the file /view... |
| CVE-2025-10772 | MEDIUM | 6.3 | 0.3% | Sep 22, 2025 | A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown function... |
| CVE-2025-10770 | MEDIUM | 6.5 | 0.4% | Sep 21, 2025 | A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDra... |
| CVE-2025-10767 | MEDIUM | 4.5 | 1.2% | Sep 21, 2025 | A vulnerability was detected in CosmodiumCS OnlyRAT up to 3.2. The affected element is the function connect/remote_uploa... |
| CVE-2025-10766 | MEDIUM | 4.3 | 0.5% | Sep 21, 2025 | A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file Event... |
| CVE-2025-10763 | MEDIUM | 6.3 | 0.3% | Sep 21, 2025 | A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by th... |
| CVE-2025-10762 | MEDIUM | 6.3 | 0.3% | Sep 21, 2025 | A vulnerability was found in kuaifan DooTask up to 1.2.49. Affected by this vulnerability is an unknown functionality of... |
| CVE-2025-10760 | MEDIUM | 6.3 | 0.3% | Sep 21, 2025 | A flaw has been found in Harness 3.3.0. This impacts the function LookupRepo of the file app/api/controller/gitspace/loo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now