2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10951 | HIGH | 7.3 | 0.6% | Sep 25, 2025 | A vulnerability was identified in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this vuln... |
| CVE-2025-10950 | MEDIUM | 6.3 | 0.3% | Sep 25, 2025 | A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the funct... |
| CVE-2025-10949 | LOW | 2.4 | 0.2% | Sep 25, 2025 | A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of... |
| CVE-2025-10542 | CRITICAL | 9.8 | 0.7% | Sep 25, 2025 | iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s... |
| CVE-2025-10541 | HIGH | 7.8 | 0.2% | Sep 25, 2025 | iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This serv... |
| CVE-2025-5494 | HIGH | 7.8 | 0.3% | Sep 25, 2025 | ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This ... |
| CVE-2025-59839 | MEDIUM | 5.4 | 0.3% | Sep 25, 2025 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em... |
| CVE-2025-59834 | CRITICAL | 9.8 | 2.3% | Sep 25, 2025 | ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.... |
| CVE-2025-59831 | HIGH | 8.8 | 2.3% | Sep 25, 2025 | git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, ... |
| CVE-2025-59426 | MEDIUM | 4.3 | 0.3% | Sep 25, 2025 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirec... |
| CVE-2025-59422 | LOW | 3.1 | 0.2% | Sep 25, 2025 | Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /con... |
| CVE-2025-57317 | HIGH | 7.5 | 0.3% | Sep 25, 2025 | apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulner... |
| CVE-2025-27261 | CRITICAL | 9.8 | 0.3% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized discl... |
| CVE-2025-26278 | HIGH | 7.5 | 0.4% | Sep 25, 2025 | A prototype pollution in the lib.set function of dref v0.1.2 allows attackers to cause a Denial of Service (DoS) via sup... |
| CVE-2025-10948 | HIGH | 8.8 | 0.7% | Sep 25, 2025 | A vulnerability has been found in MikroTik RouterOS 7. This affects the function parse_json_element of the file /rest/ip... |
| CVE-2025-10540 | MEDIUM | 6.5 | 0.1% | Sep 25, 2025 | iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM ... |
| CVE-2025-10467 | HIGH | 8.9 | 0.3% | Sep 25, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PROLIZ Comp... |
| CVE-2025-10947 | MEDIUM | 5.5 | 0.4% | Sep 25, 2025 | A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of... |
| CVE-2025-10946 | MEDIUM | 5.1 | 0.2% | Sep 25, 2025 | A vulnerability was detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. The affected element is a... |
| CVE-2025-10945 | MEDIUM | 5.1 | 0.2% | Sep 25, 2025 | A security vulnerability has been detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. Impacted is... |
| CVE-2025-10944 | MEDIUM | 5.1 | 0.2% | Sep 25, 2025 | A weakness has been identified in yi-ge get-header-ip up to 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15. This issue affects... |
| CVE-2025-10449 | HIGH | 8.6 | 0.4% | Sep 25, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems ... |
| CVE-2025-40698 | HIGH | 8.7 | 0.2% | Sep 25, 2025 | SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve,... |
| CVE-2025-10957 | HIGH | 8.7 | 0.3% | Sep 25, 2025 | This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. ... |
| CVE-2025-10943 | MEDIUM | 5.1 | 0.2% | Sep 25, 2025 | A security flaw has been discovered in MikeCen WeChat-Face-Recognition up to 6e3f72bf8547d80b59e330f1137e4aa505f492c1. T... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now