2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11717 | CRITICAL | 9.1 | 0.2% | Oct 14, 2025 | When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a passwo... |
| CVE-2025-11710 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks... |
| CVE-2025-11709 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipula... |
| CVE-2025-11708 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Th... |
| CVE-2025-10610 | CRITICAL | 9.8 | 0.3% | Oct 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Inf... |
| CVE-2025-40771 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 154... |
| CVE-2025-40765 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected... |
| CVE-2025-46581 | CRITICAL | 9.8 | 0.7% | Oct 14, 2025 | ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can ... |
| CVE-2025-42937 | CRITICAL | 9.8 | 0.7% | Oct 14, 2025 | SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated... |
| CVE-2025-42910 | CRITICAL | 9 | 0.4% | Oct 14, 2025 | Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attack... |
| CVE-2025-6919 | CRITICAL | 9.8 | 0.3% | Oct 13, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information T... |
| CVE-2025-9976 | CRITICAL | 9 | 0.9% | Oct 13, 2025 | An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE ... |
| CVE-2025-9265 | CRITICAL | 10 | 0.2% | Oct 13, 2025 | A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user ver... |
| CVE-2025-27258 | CRITICAL | 9.8 | 0.3% | Oct 13, 2025 | Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an esc... |
| CVE-2025-11665 | CRITICAL | 9.8 | 6.8% | Oct 13, 2025 | A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of... |
| CVE-2025-11664 | CRITICAL | 9.8 | 0.4% | Oct 13, 2025 | A security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element... |
| CVE-2025-11662 | CRITICAL | 9.8 | 0.4% | Oct 13, 2025 | A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. Impacted is an unknown function ... |
| CVE-2025-11661 | CRITICAL | 9.8 | 0.6% | Oct 13, 2025 | A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59... |
| CVE-2025-11660 | CRITICAL | 9.8 | 0.4% | Oct 13, 2025 | A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f90... |
| CVE-2025-11659 | CRITICAL | 9.8 | 0.5% | Oct 13, 2025 | A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Af... |
| CVE-2025-11658 | CRITICAL | 9.8 | 0.4% | Oct 13, 2025 | A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042... |
| CVE-2025-11657 | CRITICAL | 9.8 | 0.5% | Oct 13, 2025 | A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd... |
| CVE-2025-11656 | CRITICAL | 9.8 | 0.5% | Oct 13, 2025 | A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f90... |
| CVE-2025-36087 | CRITICAL | 9.8 | 0.3% | Oct 13, 2025 | IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, an... |
| CVE-2025-11631 | CRITICAL | 9.1 | 0.7% | Oct 12, 2025 | A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functional... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now