2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56676 | MEDIUM | 5.4 | 0.3% | Sep 30, 2025 | TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary p... |
| CVE-2025-56572 | HIGH | 7.5 | 0.5% | Sep 30, 2025 | An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter. |
| CVE-2025-56571 | HIGH | 7.5 | 0.4% | Sep 30, 2025 | Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper hand... |
| CVE-2025-56018 | MEDIUM | 6.1 | 0.2% | Sep 30, 2025 | SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category... |
| CVE-2025-55797 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauth... |
| CVE-2025-54477 | MEDIUM | 5.3 | 0.3% | Sep 30, 2025 | Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method. |
| CVE-2025-54476 | MEDIUM | 4.8 | 0.3% | Sep 30, 2025 | Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class. |
| CVE-2025-7779 | HIGH | 8.8 | 0.1% | Sep 30, 2025 | Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True ... |
| CVE-2025-7493 | CRITICAL | 9.1 | 0.5% | Sep 30, 2025 | A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE... |
| CVE-2025-57852 | MEDIUM | 6.4 | 0.1% | Sep 30, 2025 | A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/pas... |
| CVE-2025-56301 | HIGH | 7.5 | 0.6% | Sep 30, 2025 | An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowi... |
| CVE-2025-28016 | MEDIUM | 4.8 | 0.2% | Sep 30, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Re... |
| CVE-2025-11178 | HIGH | 7.3 | 0.2% | Sep 30, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (... |
| CVE-2025-9232 | MEDIUM | 5.9 | 2.0% | Sep 30, 2025 | Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_p... |
| CVE-2025-9231 | MEDIUM | 6.5 | 2.2% | Sep 30, 2025 | Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 ... |
| CVE-2025-9230 | HIGH | 7.5 | 1.7% | Sep 30, 2025 | Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an ou... |
| CVE-2025-52050 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_pr... |
| CVE-2025-52049 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py ... |
| CVE-2025-52047 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Inj... |
| CVE-2025-52043 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_ac... |
| CVE-2025-34217 | CRITICAL | 9.8 | 0.7% | Sep 30, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumente... |
| CVE-2025-11153 | HIGH | 7.5 | 0.2% | Sep 30, 2025 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3. |
| CVE-2025-11152 | HIGH | 8.6 | 0.3% | Sep 30, 2025 | Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.... |
| CVE-2025-10859 | MEDIUM | 4 | 0.1% | Sep 30, 2025 | Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing info... |
| CVE-2025-10217 | MEDIUM | 6 | 0.3% | Sep 30, 2025 | A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log dat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now