2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9708 | MEDIUM | 6.8 | 0.3% | Sep 16, 2025 | A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed c... |
| CVE-2025-43805 | MEDIUM | 5.3 | 0.3% | Sep 16, 2025 | Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92... |
| CVE-2025-10566 | MEDIUM | 6.1 | 0.3% | Sep 16, 2025 | A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unkno... |
| CVE-2025-49728 | MEDIUM | 4 | 0.2% | Sep 16, 2025 | Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security ... |
| CVE-2025-47967 | MEDIUM | 4.7 | 0.3% | Sep 16, 2025 | Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform... |
| CVE-2025-54237 | MEDIUM | 5.5 | 0.2% | Sep 16, 2025 | Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to m... |
| CVE-2025-59336 | MEDIUM | 6.9 | 0.4% | Sep 16, 2025 | Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of s... |
| CVE-2025-58174 | MEDIUM | 4.6 | 0.2% | Sep 16, 2025 | LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM before 9.3 allows stor... |
| CVE-2025-58749 | MEDIUM | 5.3 | 0.3% | Sep 16, 2025 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2... |
| CVE-2025-57145 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The... |
| CVE-2025-56293 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Informat... |
| CVE-2025-56289 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak ad... |
| CVE-2025-56280 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit... |
| CVE-2025-36244 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local use... |
| CVE-2025-8276 | MEDIUM | 4.3 | 0.3% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi... |
| CVE-2025-8057 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Impro... |
| CVE-2025-56276 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. ... |
| CVE-2025-39834 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_action_get_sh... |
| CVE-2025-39833 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitiali... |
| CVE-2025-39832 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix lockdep assertion on sync reset unloa... |
| CVE-2025-39831 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: fbnic: Move phylink resume out of service_task and ... |
| CVE-2025-39830 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_pool_buddy_in... |
| CVE-2025-7355 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Beefull Energy Technologies Beefull App allows Exploit... |
| CVE-2025-55834 | MEDIUM | 6.1 | 0.3% | Sep 16, 2025 | A Cross Site Scripting vulnerability in JeeWMS v.3.7 and before allows a remote attacker to obtain sensitive information... |
| CVE-2025-55117 | MEDIUM | 6.3 | 0.3% | Sep 16, 2025 | A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now