2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10608 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file ... |
| CVE-2025-59342 | MEDIUM | 5.5 | 2.8% | Sep 17, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw ... |
| CVE-2025-59341 | HIGH | 7.7 | 1.5% | Sep 17, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion... |
| CVE-2025-59339 | MEDIUM | 4.4 | 0.1% | Sep 17, 2025 | The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording tt... |
| CVE-2025-58767 | MEDIUM | 5.3 | 0.2% | Sep 17, 2025 | REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing... |
| CVE-2025-58766 | CRITICAL | 9 | 0.4% | Sep 17, 2025 | Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and ear... |
| CVE-2025-58432 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all ... |
| CVE-2025-58431 | MEDIUM | 6.2 | 0.2% | Sep 17, 2025 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earl... |
| CVE-2025-10607 | MEDIUM | 6.5 | 0.4% | Sep 17, 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the fil... |
| CVE-2025-10606 | MEDIUM | 6.1 | 0.4% | Sep 17, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file... |
| CVE-2025-10605 | MEDIUM | 6.1 | 0.4% | Sep 17, 2025 | A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the fi... |
| CVE-2025-10604 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability was identified in PHPGurukul Online Discussion Forum 1.0. This affects an unknown part of the file /admi... |
| CVE-2025-59304 | CRITICAL | 9.8 | 3.2% | Sep 17, 2025 | A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote... |
| CVE-2025-35436 | HIGH | 7.5 | 0.5% | Sep 17, 2025 | CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote... |
| CVE-2025-35435 | MEDIUM | 5.3 | 0.4% | Sep 17, 2025 | CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could caus... |
| CVE-2025-35434 | CRITICAL | 9.8 | 0.2% | Sep 17, 2025 | CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with acces... |
| CVE-2025-35433 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a ... |
| CVE-2025-35432 | HIGH | 7.5 | 0.5% | Sep 17, 2025 | CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker... |
| CVE-2025-35431 | MEDIUM | 5.4 | 0.3% | Sep 17, 2025 | CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify L... |
| CVE-2025-35430 | MEDIUM | 6.5 | 0.5% | Sep 17, 2025 | CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'... |
| CVE-2025-10603 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability was determined in PHPGurukul Online Discussion Forum 1.0. Affected by this issue is some unknown functio... |
| CVE-2025-10602 | HIGH | 8.8 | 0.3% | Sep 17, 2025 | A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknow... |
| CVE-2025-10601 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. Affected is an unknown function of the... |
| CVE-2025-10600 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /r... |
| CVE-2025-10599 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now