2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44002 | MEDIUM | 6.1 | 0.1% | Aug 26, 2025 | Race Condition in the Directory Validation Logic in the TeamViewer Full Client and Host prior version 15.69 on Windows a... |
| CVE-2025-1501 | MEDIUM | 5.3 | 0.2% | Aug 26, 2025 | An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.... |
| CVE-2025-48108 | MEDIUM | 6.5 | 0.2% | Aug 26, 2025 | Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2025-29901 | MEDIUM | 6.5 | 0.3% | Aug 26, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-6247 | MEDIUM | 4.7 | 0.2% | Aug 26, 2025 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2025-57704 | MEDIUM | 5.5 | 0.2% | Aug 26, 2025 | Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Di... |
| CVE-2025-9474 | MEDIUM | 4.5 | 0.1% | Aug 26, 2025 | A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file s... |
| CVE-2025-9440 | MEDIUM | 6.1 | 0.3% | Aug 26, 2025 | A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. A... |
| CVE-2025-9439 | MEDIUM | 6.1 | 0.3% | Aug 26, 2025 | A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by t... |
| CVE-2025-9438 | MEDIUM | 6.1 | 0.3% | Aug 26, 2025 | A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected... |
| CVE-2025-9434 | MEDIUM | 6.1 | 0.3% | Aug 26, 2025 | A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects ... |
| CVE-2025-9433 | MEDIUM | 6.1 | 0.4% | Aug 26, 2025 | A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/use... |
| CVE-2025-9432 | MEDIUM | 6.1 | 0.3% | Aug 26, 2025 | A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admi... |
| CVE-2025-9431 | MEDIUM | 6.1 | 0.3% | Aug 26, 2025 | A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation... |
| CVE-2025-9430 | MEDIUM | 4.8 | 0.2% | Aug 26, 2025 | A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/o... |
| CVE-2025-9429 | MEDIUM | 5.4 | 0.2% | Aug 26, 2025 | A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the fi... |
| CVE-2025-9422 | MEDIUM | 5.4 | 0.3% | Aug 25, 2025 | A vulnerability was found in oitcode samarium up to 0.9.6. This impacts an unknown function of the file /dashboard/team ... |
| CVE-2025-57814 | MEDIUM | 5.5 | 0.4% | Aug 25, 2025 | request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Versio... |
| CVE-2025-57804 | MEDIUM | 6.9 | 1.6% | Aug 25, 2025 | h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulne... |
| CVE-2025-52130 | MEDIUM | 5.4 | 0.2% | Aug 25, 2025 | File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw al... |
| CVE-2025-9414 | MEDIUM | 4.9 | 0.3% | Aug 25, 2025 | A vulnerability was found in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the fi... |
| CVE-2025-9409 | MEDIUM | 6.5 | 0.7% | Aug 25, 2025 | A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUplo... |
| CVE-2025-55574 | MEDIUM | 6.1 | 0.3% | Aug 25, 2025 | Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code |
| CVE-2025-55301 | MEDIUM | 6.7 | 0.2% | Aug 25, 2025 | The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local sto... |
| CVE-2025-56215 | MEDIUM | 6.5 | 0.3% | Aug 25, 2025 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now