2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61715 | — | — | — | Oct 1, 2025 | Rejected reason: Not used |
| CVE-2025-61714 | — | — | — | Oct 1, 2025 | Rejected reason: Not used |
| CVE-2025-61792 | MEDIUM | 6.4 | 0.1% | Sep 30, 2025 | Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Qu... |
| CVE-2025-55191 | MEDIUM | 5.3 | 0.4% | Sep 30, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1,... |
| CVE-2025-43826 | MEDIUM | 5.4 | 0.2% | Sep 30, 2025 | Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, ... |
| CVE-2025-24525 | HIGH | 8.7 | 0.2% | Sep 30, 2025 | Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or dec... |
| CVE-2025-56392 | HIGH | 8.1 | 0.3% | Sep 30, 2025 | An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attack... |
| CVE-2025-36262 | MEDIUM | 4.9 | 0.3% | Sep 30, 2025 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to... |
| CVE-2025-36132 | MEDIUM | 5.4 | 0.2% | Sep 30, 2025 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This ... |
| CVE-2025-10659 | CRITICAL | 9.8 | 1.2% | Sep 30, 2025 | The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that... |
| CVE-2025-56132 | HIGH | 7.3 | 0.6% | Sep 30, 2025 | LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The appli... |
| CVE-2025-43827 | MEDIUM | 4.3 | 0.3% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and o... |
| CVE-2025-57254 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allo... |
| CVE-2025-56675 | LOW | 3.5 | 0.2% | Sep 30, 2025 | The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers wi... |
| CVE-2025-56513 | CRITICAL | 9.8 | 0.4% | Sep 30, 2025 | NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An a... |
| CVE-2025-56200 | MEDIUM | 6.1 | 0.3% | Sep 30, 2025 | A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' a... |
| CVE-2025-23293 | HIGH | 8.7 | 0.2% | Sep 30, 2025 | NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause... |
| CVE-2025-23292 | MEDIUM | 4.6 | 0.2% | Sep 30, 2025 | NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Atta... |
| CVE-2025-23291 | LOW | 2.4 | 0.1% | Sep 30, 2025 | NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause... |
| CVE-2025-11195 | LOW | 3.3 | 0.1% | Sep 30, 2025 | Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can... |
| CVE-2025-10725 | CRITICAL | 9.9 | 0.7% | Sep 30, 2025 | A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for... |
| CVE-2025-56520 | MEDIUM | 5.3 | 0.6% | Sep 30, 2025 | Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_... |
| CVE-2025-56207 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Et... |
| CVE-2025-6034 | HIGH | 8.5 | 0.2% | Sep 30, 2025 | There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor ... |
| CVE-2025-6033 | HIGH | 8.5 | 0.2% | Sep 30, 2025 | There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in N... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now