2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58674 | MEDIUM | 5.9 | 0.2% | Sep 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows S... |
| CVE-2025-57638 | HIGH | 7.5 | 0.4% | Sep 23, 2025 | Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value. |
| CVE-2025-57637 | HIGH | 7.5 | 0.6% | Sep 23, 2025 | Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav... |
| CVE-2025-56146 | MEDIUM | 5.3 | 0.2% | Sep 23, 2025 | Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity. |
| CVE-2025-54081 | HIGH | 7 | 0.2% | Sep 23, 2025 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineS... |
| CVE-2025-51005 | HIGH | 7.5 | 0.4% | Sep 23, 2025 | A heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file ... |
| CVE-2025-45326 | MEDIUM | 6.5 | 0.3% | Sep 23, 2025 | An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.p... |
| CVE-2025-9197 | — | — | — | Sep 23, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-8410 | HIGH | 7.4 | 0.2% | Sep 23, 2025 | Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.This issue affects ... |
| CVE-2025-59821 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59548 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59547 | MEDIUM | 5.3 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59546 | MEDIUM | 4.8 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59545 | CRITICAL | 9 | 0.5% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-59539 | MEDIUM | 5.4 | 0.2% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-58246 | MEDIUM | 4.3 | 0.3% | Sep 23, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. Th... |
| CVE-2025-57639 | MEDIUM | 6.5 | 1.0% | Sep 23, 2025 | OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the ... |
| CVE-2025-56394 | HIGH | 7.5 | 0.4% | Sep 23, 2025 | Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slic... |
| CVE-2025-55780 | HIGH | 7.5 | 0.4% | Sep 23, 2025 | A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malfor... |
| CVE-2025-52905 | HIGH | 7.5 | 7.8% | Sep 23, 2025 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1... |
| CVE-2025-4993 | CRITICAL | 9.1 | 0.3% | Sep 23, 2025 | Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.Thi... |
| CVE-2025-4582 | HIGH | 7.1 | 0.1% | Sep 23, 2025 | Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, ... |
| CVE-2025-29084 | MEDIUM | 6.5 | 0.4% | Sep 23, 2025 | SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu... |
| CVE-2025-29083 | MEDIUM | 6.5 | 0.4% | Sep 23, 2025 | SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu... |
| CVE-2025-1255 | CRITICAL | 9.1 | 0.3% | Sep 23, 2025 | Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.Thi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now