2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57424 | HIGH | 7.3 | 0.2% | Sep 29, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile fi... |
| CVE-2025-41252 | HIGH | 7.5 | 0.9% | Sep 29, 2025 | Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit th... |
| CVE-2025-41251 | HIGH | 8.1 | 1.0% | Sep 29, 2025 | VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit thi... |
| CVE-2025-36099 | MEDIUM | 4.9 | 0.3% | Sep 29, 2025 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted... |
| CVE-2025-34196 | CRITICAL | 9.8 | 0.4% | Sep 29, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.141... |
| CVE-2025-57483 | HIGH | 8.1 | 0.3% | Sep 29, 2025 | A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary ... |
| CVE-2025-57197 | MEDIUM | 6 | 0.2% | Sep 29, 2025 | In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for ... |
| CVE-2025-56807 | MEDIUM | 6.1 | 0.2% | Sep 29, 2025 | A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrat... |
| CVE-2025-43400 | MEDIUM | 6.3 | 6.5% | Sep 29, 2025 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 1... |
| CVE-2025-41250 | HIGH | 8.5 | 0.6% | Sep 29, 2025 | VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on ... |
| CVE-2025-7104 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attac... |
| CVE-2025-61659 | MEDIUM | 6.8 | 0.1% | Sep 29, 2025 | bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name. |
| CVE-2025-56795 | CRITICAL | 9 | 0.3% | Sep 29, 2025 | Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsani... |
| CVE-2025-56234 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST p... |
| CVE-2025-56233 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN ... |
| CVE-2025-51495 | HIGH | 7.5 | 0.4% | Sep 29, 2025 | An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially cr... |
| CVE-2025-41245 | MEDIUM | 4.9 | 0.6% | Sep 29, 2025 | VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privi... |
| CVE-2025-41244 | HIGH | 7.8 | 7.9% | Sep 29, 2025 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with... |
| CVE-2025-41246 | HIGH | 7.6 | 0.3% | Sep 29, 2025 | VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls... |
| CVE-2025-11155 | MEDIUM | 6.8 | 0.2% | Sep 29, 2025 | The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is n... |
| CVE-2025-57516 | HIGH | 8.2 | 1.1% | Sep 29, 2025 | OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to e... |
| CVE-2025-56449 | HIGH | 8.2 | 0.4% | Sep 29, 2025 | A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out d... |
| CVE-2025-55795 | LOW | 3.5 | 0.3% | Sep 29, 2025 | The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership v... |
| CVE-2025-36352 | MEDIUM | 5.4 | 0.2% | Sep 29, 2025 | IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an ... |
| CVE-2025-36351 | MEDIUM | 4.3 | 0.2% | Sep 29, 2025 | IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST A... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now