2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10456 | MEDIUM | 6.5 | 0.2% | Sep 19, 2025 | A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specif... |
| CVE-2025-10146 | MEDIUM | 6.1 | 0.2% | Sep 19, 2025 | The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter i... |
| CVE-2025-8487 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capabi... |
| CVE-2025-59715 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | SMSEagle before 6.11 allows reflected XSS via a username or contact phone number. |
| CVE-2025-59714 | MEDIUM | 4.9 | 0.2% | Sep 19, 2025 | In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs. |
| CVE-2025-59712 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | Snipe-IT before 8.1.18 allows XSS. |
| CVE-2025-30755 | MEDIUM | 6.1 | 0.2% | Sep 19, 2025 | OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens t... |
| CVE-2025-47906 | MEDIUM | 6.5 | 0.5% | Sep 18, 2025 | If the PATH environment variable contains paths which are executables (rather than just directories), passing certain st... |
| CVE-2025-26503 | MEDIUM | 6.7 | 0.1% | Sep 18, 2025 | A crafted system call argument can cause memory corruption. |
| CVE-2025-36146 | MEDIUM | 4.3 | 0.2% | Sep 18, 2025 | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version informat... |
| CVE-2025-36139 | MEDIUM | 4.8 | 0.2% | Sep 18, 2025 | IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged us... |
| CVE-2025-10676 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /b... |
| CVE-2025-10675 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of t... |
| CVE-2025-10674 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController o... |
| CVE-2025-59417 | MEDIUM | 6.1 | 0.4% | Sep 18, 2025 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site sc... |
| CVE-2025-59040 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representa... |
| CVE-2025-57452 | MEDIUM | 6.1 | 0.2% | Sep 18, 2025 | In realme BackupRestore app v15.1.12_2810c08_250314, improper URI scheme handling in com.coloros.pc.PcToolMainActivity a... |
| CVE-2025-55911 | MEDIUM | 6.5 | 1.0% | Sep 18, 2025 | An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an... |
| CVE-2025-4444 | MEDIUM | 6.3 | 0.4% | Sep 18, 2025 | A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Oni... |
| CVE-2025-10669 | MEDIUM | 6.3 | 0.2% | Sep 18, 2025 | A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component... |
| CVE-2025-40678 | MEDIUM | 5.3 | 0.3% | Sep 18, 2025 | Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability ... |
| CVE-2025-9992 | MEDIUM | 6.4 | 0.2% | Sep 18, 2025 | The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-0547 | MEDIUM | 4.7 | 0.2% | Sep 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof... |
| CVE-2025-10493 | MEDIUM | 5.3 | 0.9% | Sep 18, 2025 | The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via t... |
| CVE-2025-10642 | MEDIUM | 5.1 | 0.2% | Sep 18, 2025 | A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now