2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52367 | MEDIUM | 5.4 | 4.3% | Sep 22, 2025 | Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the... |
| CVE-2025-36064 | MEDIUM | 5.9 | 0.5% | Sep 22, 2025 | IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting t... |
| CVE-2025-10811 | CRITICAL | 9.8 | 0.6% | Sep 22, 2025 | A flaw has been found in code-projects Hostel Management System 1.0. This affects an unknown function of the file /justi... |
| CVE-2025-10810 | CRITICAL | 9.8 | 0.6% | Sep 22, 2025 | A vulnerability was detected in Campcodes Online Learning Management System 1.0. The impacted element is an unknown func... |
| CVE-2025-59420 | HIGH | 7.5 | 0.2% | Sep 22, 2025 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific... |
| CVE-2025-59418 | MEDIUM | 5.5 | 0.2% | Sep 22, 2025 | BunnyPad is a note taking software. Prior to version 11.0.27000.0915, opening files greater than or equal to 20MB causes... |
| CVE-2025-57441 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Te... |
| CVE-2025-57440 | HIGH | 7.5 | 0.3% | Sep 22, 2025 | The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated ... |
| CVE-2025-57439 | HIGH | 8.8 | 0.8% | Sep 22, 2025 | Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpo... |
| CVE-2025-57438 | MEDIUM | 6.8 | 0.3% | Sep 22, 2025 | The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intend... |
| CVE-2025-57437 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service... |
| CVE-2025-55888 | HIGH | 7.3 | 0.5% | Sep 22, 2025 | Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can... |
| CVE-2025-55886 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` paramete... |
| CVE-2025-55885 | MEDIUM | 6.3 | 0.4% | Sep 22, 2025 | SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote atta... |
| CVE-2025-43953 | HIGH | 8.8 | 7.1% | Sep 22, 2025 | In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or tr... |
| CVE-2025-10809 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. The affected element is a... |
| CVE-2025-10808 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | A weakness has been identified in Campcodes Farm Management System 1.0. Impacted is an unknown function of the file /upl... |
| CVE-2025-59413 | MEDIUM | 6.5 | 0.4% | Sep 22, 2025 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription ... |
| CVE-2025-59412 | MEDIUM | 5.4 | 0.3% | Sep 22, 2025 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews featu... |
| CVE-2025-59411 | MEDIUM | 5.4 | 0.3% | Sep 22, 2025 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML a... |
| CVE-2025-59335 | HIGH | 7.1 | 0.2% | Sep 22, 2025 | CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration... |
| CVE-2025-57434 | HIGH | 8.8 | 0.5% | Sep 22, 2025 | Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The... |
| CVE-2025-57431 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malici... |
| CVE-2025-43807 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, a... |
| CVE-2025-10807 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. This issue affects some unk... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now