2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10942 | HIGH | 8.8 | 0.7% | Sep 25, 2025 | A vulnerability was identified in H3C Magic B3 up to 100R002. This affects the function AddMacList/EditMacList of the fi... |
| CVE-2025-10941 | HIGH | 8.5 | 0.1% | Sep 25, 2025 | A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functi... |
| CVE-2025-10940 | MEDIUM | 4.8 | 0.2% | Sep 25, 2025 | A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file... |
| CVE-2025-10438 | HIGH | 8.6 | 0.4% | Sep 25, 2025 | Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical ... |
| CVE-2025-21056 | MEDIUM | 6.6 | 0.2% | Sep 25, 2025 | Improper input validation in Retail Mode prior to version 5.59.4 allows self attackers to execute privileged commands on... |
| CVE-2025-54520 | HIGH | 8.6 | 0.2% | Sep 24, 2025 | Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to ... |
| CVE-2025-10894 | CRITICAL | 9.6 | 0.5% | Sep 24, 2025 | Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was pub... |
| CVE-2025-59833 | HIGH | 7.5 | 0.3% | Sep 24, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/probl... |
| CVE-2025-59827 | CRITICAL | 9.8 | 0.3% | Sep 24, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper acc... |
| CVE-2025-57324 | MEDIUM | 6.5 | 0.3% | Sep 24, 2025 | parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateContr... |
| CVE-2025-57320 | MEDIUM | 6.5 | 0.3% | Sep 24, 2025 | json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setDa... |
| CVE-2025-57319 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedR... |
| CVE-2025-57318 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject prop... |
| CVE-2025-59828 | CRITICAL | 9.8 | 0.3% | Sep 24, 2025 | Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.... |
| CVE-2025-59824 | MEDIUM | 5.4 | 0.2% | Sep 24, 2025 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLi... |
| CVE-2025-57329 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability i... |
| CVE-2025-57328 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | toggle-array is a package designed to enables a property on the object at the specified index, while disabling the prope... |
| CVE-2025-57327 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config funct... |
| CVE-2025-57326 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers ... |
| CVE-2025-57325 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes a... |
| CVE-2025-57323 | HIGH | 7.5 | 0.4% | Sep 24, 2025 | mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vul... |
| CVE-2025-57321 | CRITICAL | 9.8 | 0.4% | Sep 24, 2025 | A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 all... |
| CVE-2025-59525 | MEDIUM | 6.1 | 0.3% | Sep 24, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization... |
| CVE-2025-59251 | HIGH | 7.6 | 0.5% | Sep 24, 2025 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-57351 | MEDIUM | 6.5 | 0.4% | Sep 24, 2025 | A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now