2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10707 | HIGH | 8.8 | 0.4% | Sep 19, 2025 | A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessage... |
| CVE-2025-10468 | HIGH | 7.5 | 0.4% | Sep 19, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus ... |
| CVE-2025-8531 | MEDIUM | 6.8 | 1.0% | Sep 19, 2025 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03... |
| CVE-2025-10719 | MEDIUM | 5.3 | 0.3% | Sep 19, 2025 | Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers wit... |
| CVE-2025-10630 | MEDIUM | 4.3 | 0.3% | Sep 19, 2025 | Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to ... |
| CVE-2025-9906 | HIGH | 7.3 | 0.2% | Sep 19, 2025 | The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One c... |
| CVE-2025-9905 | HIGH | 7.3 | 0.2% | Sep 19, 2025 | The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One c... |
| CVE-2025-10647 | HIGH | 8.8 | 0.8% | Sep 19, 2025 | The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2025-7702 | MEDIUM | 4.7 | 0.2% | Sep 19, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry ... |
| CVE-2025-7403 | MEDIUM | 6.5 | 0.2% | Sep 19, 2025 | Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes a... |
| CVE-2025-5948 | CRITICAL | 9.8 | 0.4% | Sep 19, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2025-10458 | HIGH | 7.6 | 0.2% | Sep 19, 2025 | Parameters are not validated or sanitized, and are later used in various internal operations. |
| CVE-2025-10457 | HIGH | 8.1 | 0.4% | Sep 19, 2025 | The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, w... |
| CVE-2025-10456 | MEDIUM | 6.5 | 0.2% | Sep 19, 2025 | A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specif... |
| CVE-2025-5955 | HIGH | 8.1 | 0.4% | Sep 19, 2025 | The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inc... |
| CVE-2025-10146 | MEDIUM | 6.1 | 0.2% | Sep 19, 2025 | The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter i... |
| CVE-2025-8487 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capabi... |
| CVE-2025-59717 | CRITICAL | 9.8 | 0.4% | Sep 19, 2025 | In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .i... |
| CVE-2025-7937 | HIGH | 7.2 | 0.3% | Sep 19, 2025 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can upda... |
| CVE-2025-59715 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | SMSEagle before 6.11 allows reflected XSS via a username or contact phone number. |
| CVE-2025-59714 | MEDIUM | 4.9 | 0.2% | Sep 19, 2025 | In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs. |
| CVE-2025-59713 | HIGH | 8.1 | 0.3% | Sep 19, 2025 | Snipe-IT before 8.1.18 allows unsafe deserialization. |
| CVE-2025-59712 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | Snipe-IT before 8.1.18 allows XSS. |
| CVE-2025-59678 | — | — | — | Sep 19, 2025 | Rejected reason: Not used |
| CVE-2025-59677 | — | — | — | Sep 19, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now