2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10673 | CRITICAL | 9.8 | 0.5% | Sep 18, 2025 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unk... |
| CVE-2025-10672 | HIGH | 7.8 | 0.2% | Sep 18, 2025 | A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIB... |
| CVE-2025-10671 | LOW | 3.7 | 0.4% | Sep 18, 2025 | A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of t... |
| CVE-2025-4444 | MEDIUM | 6.3 | 0.4% | Sep 18, 2025 | A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Oni... |
| CVE-2025-10670 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A flaw has been found in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some ... |
| CVE-2025-10669 | MEDIUM | 6.3 | 0.2% | Sep 18, 2025 | A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component... |
| CVE-2025-10668 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A security vulnerability has been detected in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of ... |
| CVE-2025-10667 | CRITICAL | 9.8 | 0.5% | Sep 18, 2025 | A weakness has been identified in itsourcecode Online Discussion Forum 1.0. Affected by this issue is some unknown funct... |
| CVE-2025-10666 | CRITICAL | 9.8 | 3.0% | Sep 18, 2025 | A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_410... |
| CVE-2025-40678 | MEDIUM | 5.3 | 0.3% | Sep 18, 2025 | Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability ... |
| CVE-2025-40677 | HIGH | 8.7 | 0.6% | Sep 18, 2025 | SQL injection vulnerability in Summar Software´s Portal del Empleado. This vulnerability allows an attacker to retrieve,... |
| CVE-2025-10665 | CRITICAL | 9.8 | 0.3% | Sep 18, 2025 | A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Affected ... |
| CVE-2025-10664 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability was determined in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /create-ticket.... |
| CVE-2025-10207 | HIGH | 7.5 | 0.3% | Sep 18, 2025 | Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. |
| CVE-2025-10663 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability was found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /my... |
| CVE-2025-10662 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /admin_memb... |
| CVE-2025-9992 | MEDIUM | 6.4 | 0.2% | Sep 18, 2025 | The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-8565 | HIGH | 8.1 | 0.3% | Sep 18, 2025 | The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul... |
| CVE-2025-30187 | LOW | 3.7 | 0.3% | Sep 18, 2025 | In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries,... |
| CVE-2025-6237 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file del... |
| CVE-2025-0547 | MEDIUM | 4.7 | 0.2% | Sep 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof... |
| CVE-2025-10493 | MEDIUM | 5.3 | 0.9% | Sep 18, 2025 | The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via t... |
| CVE-2025-9083 | CRITICAL | 9.8 | 0.5% | Sep 18, 2025 | The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticate... |
| CVE-2025-8942 | CRITICAL | 9.1 | 0.3% | Sep 18, 2025 | The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an a... |
| CVE-2025-5305 | CRITICAL | 9.8 | 0.2% | Sep 18, 2025 | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now