2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54807 | CRITICAL | 9.8 | 0.7% | Sep 18, 2025 | The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker... |
| CVE-2025-54754 | HIGH | 8.6 | 0.2% | Sep 18, 2025 | An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded passw... |
| CVE-2025-53947 | HIGH | 7.7 | 0.1% | Sep 18, 2025 | A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerabili... |
| CVE-2025-47698 | HIGH | 8.6 | 0.2% | Sep 18, 2025 | An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credenti... |
| CVE-2025-30519 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standa... |
| CVE-2025-10689 | CRITICAL | 9.8 | 4.6% | Sep 18, 2025 | A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.... |
| CVE-2025-59424 | HIGH | 7.3 | 0.3% | Sep 18, 2025 | LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerabi... |
| CVE-2025-10688 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow... |
| CVE-2025-47906 | MEDIUM | 6.5 | 0.5% | Sep 18, 2025 | If the PATH environment variable contains paths which are executables (rather than just directories), passing certain st... |
| CVE-2025-26503 | MEDIUM | 6.7 | 0.1% | Sep 18, 2025 | A crafted system call argument can cause memory corruption. |
| CVE-2025-10650 | LOW | 1.8 | 0.1% | Sep 18, 2025 | SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys und... |
| CVE-2025-10687 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability was found in SourceCodester Responsive E-Learning System 1.0. This affects an unknown part of the file /... |
| CVE-2025-55912 | HIGH | 7.3 | 1.4% | Sep 18, 2025 | An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in ... |
| CVE-2025-50255 | HIGH | 7.8 | 0.1% | Sep 18, 2025 | Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request... |
| CVE-2025-36146 | MEDIUM | 4.3 | 0.2% | Sep 18, 2025 | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version informat... |
| CVE-2025-36143 | HIGH | 7.2 | 0.3% | Sep 18, 2025 | IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the syste... |
| CVE-2025-36139 | MEDIUM | 4.8 | 0.2% | Sep 18, 2025 | IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged us... |
| CVE-2025-10676 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /b... |
| CVE-2025-10675 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of t... |
| CVE-2025-10674 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController o... |
| CVE-2025-59421 | LOW | 2.7 | 0.4% | Sep 18, 2025 | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-... |
| CVE-2025-59417 | MEDIUM | 6.1 | 0.4% | Sep 18, 2025 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site sc... |
| CVE-2025-59040 | MEDIUM | 4.3 | 0.3% | Sep 18, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representa... |
| CVE-2025-57452 | MEDIUM | 6.1 | 0.2% | Sep 18, 2025 | In realme BackupRestore app v15.1.12_2810c08_250314, improper URI scheme handling in com.coloros.pc.PcToolMainActivity a... |
| CVE-2025-55911 | MEDIUM | 6.5 | 1.0% | Sep 18, 2025 | An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now