2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58319 | HIGH | 7.8 | 0.1% | Sep 24, 2025 | Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att... |
| CVE-2025-58317 | HIGH | 7.8 | 0.3% | Sep 24, 2025 | Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att... |
| CVE-2025-59930 | — | — | — | Sep 24, 2025 | Rejected reason: Not used |
| CVE-2025-59929 | — | — | — | Sep 24, 2025 | Rejected reason: Not used |
| CVE-2025-59928 | — | — | — | Sep 24, 2025 | Rejected reason: Not used |
| CVE-2025-59927 | — | — | — | Sep 24, 2025 | Rejected reason: Not used |
| CVE-2025-59926 | — | — | — | Sep 24, 2025 | Rejected reason: Not used |
| CVE-2025-59925 | — | — | — | Sep 24, 2025 | Rejected reason: Not used |
| CVE-2025-59924 | — | — | — | Sep 24, 2025 | Rejected reason: Not used |
| CVE-2025-43819 | MEDIUM | 6.5 | 0.2% | Sep 24, 2025 | A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.... |
| CVE-2025-43779 | MEDIUM | 6.1 | 0.2% | Sep 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024... |
| CVE-2025-58473 | HIGH | 8.2 | 0.3% | Sep 23, 2025 | An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f... |
| CVE-2025-57882 | HIGH | 8.2 | 0.3% | Sep 23, 2025 | An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running f... |
| CVE-2025-55069 | HIGH | 8.7 | 0.3% | Sep 23, 2025 | A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the C... |
| CVE-2025-55038 | HIGH | 7.6 | 0.2% | Sep 23, 2025 | An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Thro... |
| CVE-2025-59484 | HIGH | 8.7 | 0.1% | Sep 23, 2025 | The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The ... |
| CVE-2025-58069 | MEDIUM | 6.9 | 0.2% | Sep 23, 2025 | The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerabili... |
| CVE-2025-54855 | MEDIUM | 4.2 | 0.1% | Sep 23, 2025 | Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability... |
| CVE-2025-59826 | HIGH | 7.6 | 0.2% | Sep 23, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, pote... |
| CVE-2025-58354 | MEDIUM | 6.9 | 0.3% | Sep 23, 2025 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2025-56311 | MEDIUM | 6.5 | 0.1% | Sep 23, 2025 | In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authentic... |
| CVE-2025-59825 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-... |
| CVE-2025-57636 | MEDIUM | 6.5 | 1.1% | Sep 23, 2025 | OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injecti... |
| CVE-2025-59822 | HIGH | 7.5 | 0.3% | Sep 23, 2025 | Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s ... |
| CVE-2025-59534 | HIGH | 7.8 | 0.9% | Sep 23, 2025 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now