2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36893 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could ... |
| CVE-2025-8268 | MEDIUM | 6.5 | 0.3% | Sep 3, 2025 | The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability che... |
| CVE-2025-56139 | MEDIUM | 5.3 | 0.3% | Sep 3, 2025 | LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, descript... |
| CVE-2025-9923 | MEDIUM | 6.1 | 0.4% | Sep 3, 2025 | A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. ... |
| CVE-2025-36193 | MEDIUM | 6.7 | 0.1% | Sep 3, 2025 | IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could all... |
| CVE-2025-20335 | MEDIUM | 5.3 | 0.3% | Sep 3, 2025 | A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C... |
| CVE-2025-20330 | MEDIUM | 6.1 | 0.2% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service ... |
| CVE-2025-20328 | MEDIUM | 5.4 | 0.2% | Sep 3, 2025 | A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attack... |
| CVE-2025-20291 | MEDIUM | 6.1 | 0.2% | Sep 3, 2025 | A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted We... |
| CVE-2025-20280 | MEDIUM | 4.8 | 0.2% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2025-20270 | MEDIUM | 6.5 | 0.3% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2025-9922 | MEDIUM | 6.1 | 0.4% | Sep 3, 2025 | A security vulnerability has been detected in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability i... |
| CVE-2025-9921 | MEDIUM | 5.4 | 0.3% | Sep 3, 2025 | A weakness has been identified in code-projects POS Pharmacy System 1.0. Affected is an unknown function of the file /ma... |
| CVE-2025-9867 | MEDIUM | 5.4 | 0.3% | Sep 3, 2025 | Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker t... |
| CVE-2025-9865 | MEDIUM | 5.4 | 0.2% | Sep 3, 2025 | Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who... |
| CVE-2025-56761 | MEDIUM | 5.4 | 0.2% | Sep 3, 2025 | Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar f... |
| CVE-2025-56760 | MEDIUM | 4.3 | 0.3% | Sep 3, 2025 | When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint co... |
| CVE-2025-56689 | MEDIUM | 4.6 | 1.3% | Sep 3, 2025 | One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/... |
| CVE-2025-56498 | MEDIUM | 5.3 | 1.7% | Sep 3, 2025 | An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interf... |
| CVE-2025-56435 | MEDIUM | 5.3 | 0.3% | Sep 3, 2025 | SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file... |
| CVE-2025-55944 | MEDIUM | 6.1 | 0.3% | Sep 3, 2025 | Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a n... |
| CVE-2025-9824 | MEDIUM | 5.9 | 0.3% | Sep 3, 2025 | ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used ... |
| CVE-2025-9823 | MEDIUM | 4.8 | 0.3% | Sep 3, 2025 | SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of a... |
| CVE-2025-58641 | MEDIUM | 5.4 | 0.2% | Sep 3, 2025 | Server-Side Request Forgery (SSRF) vulnerability in kamleshyadav Exit Intent Popup exitintentpopup allows Server Side Re... |
| CVE-2025-58640 | MEDIUM | 6.5 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Docum... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now