2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9902 | HIGH | 7.5 | 0.3% | Oct 13, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trad... |
| CVE-2025-6919 | CRITICAL | 9.8 | 0.3% | Oct 13, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information T... |
| CVE-2025-9337 | MEDIUM | 6.8 | 0.1% | Oct 13, 2025 | A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a speciall... |
| CVE-2025-9336 | MEDIUM | 6.8 | 0.1% | Oct 13, 2025 | A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipu... |
| CVE-2025-11184 | MEDIUM | 6.9 | 0.4% | Oct 13, 2025 | Cross-site scripting vulnerability in QGIS QWC2 Registration GUI <=v2025.03.31 allows an authorized attacker to plant ar... |
| CVE-2025-11183 | MEDIUM | 6.9 | 0.4% | Oct 13, 2025 | Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 <2025.08.14 allows an authorized attacker to plant ar... |
| CVE-2025-10720 | MEDIUM | 6.5 | 0.3% | Oct 13, 2025 | The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However... |
| CVE-2025-9968 | HIGH | 8.5 | 0.2% | Oct 13, 2025 | A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggere... |
| CVE-2025-9976 | CRITICAL | 9 | 0.9% | Oct 13, 2025 | An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE ... |
| CVE-2025-11675 | HIGH | 8.6 | 0.5% | Oct 13, 2025 | Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote atta... |
| CVE-2025-11674 | MEDIUM | 6.9 | 0.3% | Oct 13, 2025 | SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to... |
| CVE-2025-11673 | HIGH | 8.6 | 0.5% | Oct 13, 2025 | SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploi... |
| CVE-2025-11672 | MEDIUM | 6.9 | 0.3% | Oct 13, 2025 | Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthentic... |
| CVE-2025-11671 | MEDIUM | 6.9 | 0.3% | Oct 13, 2025 | Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthentic... |
| CVE-2025-11668 | HIGH | 7.2 | 0.4% | Oct 13, 2025 | A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown func... |
| CVE-2025-11667 | HIGH | 8.8 | 0.4% | Oct 13, 2025 | A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown fun... |
| CVE-2025-10558 | MEDIUM | 6.1 | 0.2% | Oct 13, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows a... |
| CVE-2025-10557 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator ... |
| CVE-2025-10556 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager fro... |
| CVE-2025-10552 | MEDIUM | 6.1 | 0.2% | Oct 13, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an ... |
| CVE-2025-9265 | CRITICAL | 10 | 0.2% | Oct 13, 2025 | A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user ver... |
| CVE-2025-8915 | HIGH | 8.7 | 0.2% | Oct 13, 2025 | Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-i... |
| CVE-2025-27259 | MEDIUM | 5.4 | 0.2% | Oct 13, 2025 | Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limite... |
| CVE-2025-27258 | CRITICAL | 9.8 | 0.3% | Oct 13, 2025 | Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an esc... |
| CVE-2025-11666 | HIGH | 7 | 0.1% | Oct 13, 2025 | A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now