2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59676 | — | — | — | Sep 19, 2025 | Rejected reason: Not used |
| CVE-2025-59675 | — | — | — | Sep 19, 2025 | Rejected reason: Not used |
| CVE-2025-59674 | — | — | — | Sep 19, 2025 | Rejected reason: Not used |
| CVE-2025-59673 | — | — | — | Sep 19, 2025 | Rejected reason: Not used |
| CVE-2025-59672 | — | — | — | Sep 19, 2025 | Rejected reason: Not used |
| CVE-2025-59671 | — | — | — | Sep 19, 2025 | Rejected reason: Not used |
| CVE-2025-59670 | — | — | — | Sep 19, 2025 | Rejected reason: Not used |
| CVE-2025-10690 | CRITICAL | 9.8 | 0.7% | Sep 19, 2025 | The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads du... |
| CVE-2025-6198 | HIGH | 7.2 | 0.3% | Sep 19, 2025 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up... |
| CVE-2025-30755 | MEDIUM | 6.1 | 0.2% | Sep 19, 2025 | OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens t... |
| CVE-2025-59692 | LOW | 3.7 | 0.2% | Sep 18, 2025 | PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing ipta... |
| CVE-2025-59691 | LOW | 3.7 | 0.2% | Sep 18, 2025 | PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon netwo... |
| CVE-2025-59220 | HIGH | 7 | 0.2% | Sep 18, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service... |
| CVE-2025-59216 | HIGH | 7 | 0.2% | Sep 18, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon... |
| CVE-2025-59215 | HIGH | 7 | 0.3% | Sep 18, 2025 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54860 | HIGH | 7.7 | 0.1% | Sep 18, 2025 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow manage... |
| CVE-2025-54818 | HIGH | 8.6 | 0.1% | Sep 18, 2025 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform manage... |
| CVE-2025-54810 | HIGH | 8.6 | 0.2% | Sep 18, 2025 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform manage... |
| CVE-2025-54497 | HIGH | 8.1 | 0.3% | Sep 18, 2025 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management ope... |
| CVE-2025-53969 | HIGH | 8.8 | 0.4% | Sep 18, 2025 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port ... |
| CVE-2025-52873 | HIGH | 8.1 | 0.3% | Sep 18, 2025 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management oper... |
| CVE-2025-10035 | CRITICAL | 9.8 | 99.6% | Sep 18, 2025 | A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged ... |
| CVE-2025-57295 | HIGH | 8 | 0.4% | Sep 18, 2025 | H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credenti... |
| CVE-2025-57293 | HIGH | 8.8 | 1.7% | Sep 18, 2025 | A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the s... |
| CVE-2025-55068 | HIGH | 8.8 | 0.4% | Sep 18, 2025 | Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacke... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now