2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0672 | LOW | 3.8 | 0.2% | Sep 23, 2025 | An authentication bypass vulnerability exists in multiple WSO2 products when FIDO authentication is enabled. When a user... |
| CVE-2025-0209 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due... |
| CVE-2025-9900 | HIGH | 8.8 | 0.7% | Sep 23, 2025 | A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes ... |
| CVE-2025-56304 | MEDIUM | 6.1 | 0.2% | Sep 23, 2025 | Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page. |
| CVE-2025-0663 | MEDIUM | 6.8 | 0.2% | Sep 23, 2025 | A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Ada... |
| CVE-2025-5717 | HIGH | 7.2 | 0.6% | Sep 23, 2025 | An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input valida... |
| CVE-2025-57407 | MEDIUM | 5.4 | 0.2% | Sep 23, 2025 | A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticat... |
| CVE-2025-4760 | MEDIUM | 4.8 | 0.2% | Sep 23, 2025 | An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper valida... |
| CVE-2025-9844 | HIGH | 8.8 | 0.4% | Sep 23, 2025 | Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable... |
| CVE-2025-8354 | HIGH | 7.8 | 0.2% | Sep 23, 2025 | A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A maliciou... |
| CVE-2025-6921 | HIGH | 7.5 | 0.5% | Sep 23, 2025 | The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (R... |
| CVE-2025-9846 | CRITICAL | 10 | 1.0% | Sep 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry In... |
| CVE-2025-10184 | HIGH | 8.2 | 3.7% | Sep 23, 2025 | The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provi... |
| CVE-2025-9966 | HIGH | 7.3 | 0.3% | Sep 23, 2025 | Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service ... |
| CVE-2025-9965 | CRITICAL | 9.3 | 0.7% | Sep 23, 2025 | Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any ap... |
| CVE-2025-9964 | HIGH | 8.6 | 0.2% | Sep 23, 2025 | No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. T... |
| CVE-2025-9963 | CRITICAL | 9.4 | 0.2% | Sep 23, 2025 | A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with r... |
| CVE-2025-10244 | HIGH | 8.7 | 0.4% | Sep 23, 2025 | A maliciously crafted HTML payload, when rendered by the Autodesk Fusion desktop application, can trigger a Stored Cross... |
| CVE-2025-9962 | CRITICAL | 10 | 1.4% | Sep 23, 2025 | A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without prior authenticatio... |
| CVE-2025-9342 | MEDIUM | 6.5 | 0.3% | Sep 23, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privile... |
| CVE-2025-7106 | MEDIUM | 5.3 | 0.3% | Sep 23, 2025 | danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `c... |
| CVE-2025-10412 | CRITICAL | 9.8 | 0.6% | Sep 23, 2025 | The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl... |
| CVE-2025-9798 | HIGH | 8.9 | 0.3% | Sep 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Soft... |
| CVE-2025-10857 | CRITICAL | 9.8 | 0.5% | Sep 23, 2025 | A security flaw has been discovered in Campcodes Point of Sale System POS 1.0. Affected by this issue is some unknown fu... |
| CVE-2025-10147 | CRITICAL | 9.8 | 0.9% | Sep 23, 2025 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now