2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9273 | MEDIUM | 4.3 | 0.5% | Sep 2, 2025 | CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers... |
| CVE-2025-36162 | MEDIUM | 4.3 | 0.2% | Sep 2, 2025 | IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive ... |
| CVE-2025-55824 | MEDIUM | 6.5 | 0.2% | Sep 2, 2025 | ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execut... |
| CVE-2025-55476 | MEDIUM | 6.5 | 0.2% | Sep 2, 2025 | FireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint... |
| CVE-2025-51966 | MEDIUM | 6.1 | 0.2% | Sep 2, 2025 | A cross-site scripting (XSS) vulnerability exists in the PDF preview functionality of uTools thru 7.1.1. When a user pre... |
| CVE-2025-50565 | MEDIUM | 6.5 | 0.2% | Sep 2, 2025 | Doubo ERP 1.0 has an SQL injection vulnerability due to a lack of filtering of user input, which can be remotely initiat... |
| CVE-2025-32100 | MEDIUM | 6.5 | 0.2% | Sep 2, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-32098 | MEDIUM | 5.3 | 0.2% | Sep 2, 2025 | An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges ... |
| CVE-2025-9828 | MEDIUM | 5.9 | 0.3% | Sep 2, 2025 | A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the compone... |
| CVE-2025-55474 | MEDIUM | 6.1 | 0.3% | Sep 2, 2025 | Many Notes 0.10.1 is vulnerable to Cross Site Scripting (XSS), which allows malicious Markdown files to execute JavaScri... |
| CVE-2025-55473 | MEDIUM | 6.1 | 0.3% | Sep 2, 2025 | Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scriptin... |
| CVE-2025-55472 | MEDIUM | 6.5 | 0.3% | Sep 2, 2025 | SQL Injection vulnerability exists in Tirreno v0.9.5, specifically in the /admin/loadUsers API endpoint. The vulnerabili... |
| CVE-2025-55373 | MEDIUM | 5.3 | 0.5% | Sep 2, 2025 | Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to... |
| CVE-2025-57611 | MEDIUM | 5.3 | 0.3% | Sep 2, 2025 | An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the dump() ... |
| CVE-2025-55372 | MEDIUM | 5.3 | 0.3% | Sep 2, 2025 | An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code vi... |
| CVE-2025-50757 | MEDIUM | 6.5 | 1.8% | Sep 2, 2025 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the user... |
| CVE-2025-50755 | MEDIUM | 6.5 | 1.1% | Sep 2, 2025 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the comm... |
| CVE-2025-46047 | MEDIUM | 6.5 | 0.3% | Sep 2, 2025 | A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows... |
| CVE-2025-0670 | MEDIUM | 4.7 | 0.2% | Sep 2, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft ProKuafor allows Resource Leak Exposure. Thi... |
| CVE-2025-56254 | MEDIUM | 4.3 | 0.2% | Sep 2, 2025 | PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in lea... |
| CVE-2025-52548 | MEDIUM | 4.9 | 0.3% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enab... |
| CVE-2025-52546 | MEDIUM | 6.1 | 0.2% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta... |
| CVE-2025-0640 | MEDIUM | 4.7 | 0.2% | Sep 2, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft OctoCloud allows Resource Leak Exposure. Thi... |
| CVE-2025-41031 | MEDIUM | 6.9 | 0.3% | Sep 2, 2025 | Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other us... |
| CVE-2025-41030 | MEDIUM | 6.9 | 0.3% | Sep 2, 2025 | Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain informat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now