2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10806 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. This vulnerability affects unkno... |
| CVE-2025-57682 | MEDIUM | 6.5 | 0.6% | Sep 22, 2025 | Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary fil... |
| CVE-2025-57605 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users ... |
| CVE-2025-57602 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared... |
| CVE-2025-57601 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access ... |
| CVE-2025-57433 | MEDIUM | 6.5 | 0.3% | Sep 22, 2025 | The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POS... |
| CVE-2025-57432 | CRITICAL | 9.8 | 0.6% | Sep 22, 2025 | Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This s... |
| CVE-2025-57430 | HIGH | 7.5 | 0.4% | Sep 22, 2025 | Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When access... |
| CVE-2025-36202 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute co... |
| CVE-2025-36037 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authe... |
| CVE-2025-35042 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Ins... |
| CVE-2025-35041 | HIGH | 7.7 | 0.3% | Sep 22, 2025 | Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A r... |
| CVE-2025-10805 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A vulnerability was determined in Campcodes Online Beauty Parlor Management System 1.0. This affects an unknown part of ... |
| CVE-2025-10804 | HIGH | 8.8 | 0.4% | Sep 22, 2025 | A vulnerability was found in Campcodes Online Beauty Parlor Management System 1.0. Affected by this issue is some unknow... |
| CVE-2025-9038 | HIGH | 7.5 | 0.1% | Sep 22, 2025 | Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Es... |
| CVE-2025-10803 | HIGH | 8.8 | 0.7% | Sep 22, 2025 | A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of... |
| CVE-2025-10802 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | A flaw has been found in code-projects Online Bidding System 1.0. Affected is an unknown function of the file /administr... |
| CVE-2025-56075 | MEDIUM | 5.4 | 0.2% | Sep 22, 2025 | A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing... |
| CVE-2025-56074 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticket... |
| CVE-2025-51006 | HIGH | 7.8 | 0.2% | Sep 22, 2025 | Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function i... |
| CVE-2025-10801 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. This affects an unkno... |
| CVE-2025-10800 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | A weakness has been identified in itsourcecode Online Discussion Forum 1.0. The impacted element is an unknown function ... |
| CVE-2025-59797 | MEDIUM | 5.8 | 0.3% | Sep 22, 2025 | Profession Fit 5.0.99 Build 44910 allows authorization bypass via a direct request for /api/challenges/{id} and also URL... |
| CVE-2025-10854 | HIGH | 8.1 | 0.4% | Sep 22, 2025 | The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is inte... |
| CVE-2025-10799 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | A security flaw has been discovered in code-projects Hostel Management System 1.0. The affected element is an unknown fu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now