2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10642 | MEDIUM | 5.1 | 0.2% | Sep 18, 2025 | A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts... |
| CVE-2025-10632 | MEDIUM | 5.4 | 0.3% | Sep 18, 2025 | A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unk... |
| CVE-2025-10631 | MEDIUM | 5.4 | 0.3% | Sep 18, 2025 | A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of ... |
| CVE-2025-23337 | MEDIUM | 6.7 | 0.1% | Sep 17, 2025 | NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a mal... |
| CVE-2025-59415 | MEDIUM | 5.4 | 0.2% | Sep 17, 2025 | Frappe Learning is a learning system that helps users structure their content. In versions 2.34.1 and below, there is a ... |
| CVE-2025-10619 | MEDIUM | 6.3 | 1.6% | Sep 17, 2025 | A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of th... |
| CVE-2025-59354 | MEDIUM | 5.3 | 0.2% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 us... |
| CVE-2025-59351 | MEDIUM | 5.3 | 0.3% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return ... |
| CVE-2025-59350 | MEDIUM | 5.3 | 0.3% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access contro... |
| CVE-2025-59347 | MEDIUM | 6.5 | 0.2% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disab... |
| CVE-2025-59346 | MEDIUM | 5.3 | 0.2% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a... |
| CVE-2025-37122 | MEDIUM | 6.1 | 0.3% | Sep 17, 2025 | A vulnerability in the web-based management interface of network access control services could allow an unauthenticated ... |
| CVE-2025-10614 | MEDIUM | 6.1 | 0.4% | Sep 17, 2025 | A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This a... |
| CVE-2025-56648 | MEDIUM | 6.5 | 0.2% | Sep 17, 2025 | npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPReque... |
| CVE-2025-59342 | MEDIUM | 5.5 | 2.8% | Sep 17, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw ... |
| CVE-2025-59339 | MEDIUM | 4.4 | 0.1% | Sep 17, 2025 | The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording tt... |
| CVE-2025-58767 | MEDIUM | 5.3 | 0.2% | Sep 17, 2025 | REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing... |
| CVE-2025-58431 | MEDIUM | 6.2 | 0.2% | Sep 17, 2025 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earl... |
| CVE-2025-10607 | MEDIUM | 6.5 | 0.4% | Sep 17, 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the fil... |
| CVE-2025-10606 | MEDIUM | 6.1 | 0.4% | Sep 17, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file... |
| CVE-2025-10605 | MEDIUM | 6.1 | 0.4% | Sep 17, 2025 | A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the fi... |
| CVE-2025-35435 | MEDIUM | 5.3 | 0.4% | Sep 17, 2025 | CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could caus... |
| CVE-2025-35431 | MEDIUM | 5.4 | 0.3% | Sep 17, 2025 | CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify L... |
| CVE-2025-35430 | MEDIUM | 6.5 | 0.5% | Sep 17, 2025 | CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'... |
| CVE-2025-9862 | MEDIUM | 6.5 | 0.5% | Sep 17, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue aff... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now