2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59342 | MEDIUM | 5.5 | 2.8% | Sep 17, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw ... |
| CVE-2025-59339 | MEDIUM | 4.4 | 0.1% | Sep 17, 2025 | The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording tt... |
| CVE-2025-58767 | MEDIUM | 5.3 | 0.2% | Sep 17, 2025 | REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing... |
| CVE-2025-58431 | MEDIUM | 6.2 | 0.2% | Sep 17, 2025 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earl... |
| CVE-2025-10607 | MEDIUM | 6.5 | 0.4% | Sep 17, 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the fil... |
| CVE-2025-10606 | MEDIUM | 6.1 | 0.4% | Sep 17, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file... |
| CVE-2025-10605 | MEDIUM | 6.1 | 0.4% | Sep 17, 2025 | A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the fi... |
| CVE-2025-35435 | MEDIUM | 5.3 | 0.4% | Sep 17, 2025 | CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could caus... |
| CVE-2025-35431 | MEDIUM | 5.4 | 0.3% | Sep 17, 2025 | CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify L... |
| CVE-2025-35430 | MEDIUM | 6.5 | 0.5% | Sep 17, 2025 | CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'... |
| CVE-2025-9862 | MEDIUM | 6.5 | 0.5% | Sep 17, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue aff... |
| CVE-2025-57055 | MEDIUM | 6.5 | 0.4% | Sep 17, 2025 | WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An ... |
| CVE-2025-54390 | MEDIUM | 6.3 | 0.2% | Sep 17, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (... |
| CVE-2025-59476 | MEDIUM | 5.3 | 0.3% | Sep 17, 2025 | Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted fr... |
| CVE-2025-59475 | MEDIUM | 4.3 | 0.4% | Sep 17, 2025 | Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profil... |
| CVE-2025-59474 | MEDIUM | 5.3 | 4.7% | Sep 17, 2025 | Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intent... |
| CVE-2025-55904 | MEDIUM | 4 | 0.2% | Sep 17, 2025 | Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference wh... |
| CVE-2025-50709 | MEDIUM | 4.3 | 0.3% | Sep 17, 2025 | An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter |
| CVE-2025-8463 | MEDIUM | 5.3 | 0.2% | Sep 17, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forcef... |
| CVE-2025-54467 | MEDIUM | 5.3 | 0.2% | Sep 17, 2025 | When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the pass... |
| CVE-2025-53884 | MEDIUM | 5.3 | 0.2% | Sep 17, 2025 | NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table a... |
| CVE-2025-0879 | MEDIUM | 4.7 | 0.2% | Sep 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shopside So... |
| CVE-2025-8999 | MEDIUM | 5.3 | 0.3% | Sep 17, 2025 | The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t... |
| CVE-2025-0546 | MEDIUM | 4.7 | 0.2% | Sep 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Ren... |
| CVE-2025-10591 | MEDIUM | 5.4 | 0.2% | Sep 17, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now