2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10157 | HIGH | 7.8 | 0.8% | Sep 17, 2025 | A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remot... |
| CVE-2025-0546 | MEDIUM | 4.7 | 0.2% | Sep 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Ren... |
| CVE-2025-10591 | MEDIUM | 5.4 | 0.2% | Sep 17, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet... |
| CVE-2025-10590 | MEDIUM | 6.1 | 0.3% | Sep 17, 2025 | A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of th... |
| CVE-2025-10156 | CRITICAL | 9.8 | 1.4% | Sep 17, 2025 | An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 pickles... |
| CVE-2025-10155 | HIGH | 7.8 | 0.8% | Sep 17, 2025 | An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0... |
| CVE-2025-0420 | MEDIUM | 4.7 | 0.2% | Sep 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof... |
| CVE-2025-59458 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54... |
| CVE-2025-59457 | HIGH | 7.7 | 0.8% | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows |
| CVE-2025-59456 | MEDIUM | 5.5 | 12.1% | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload |
| CVE-2025-59455 | MEDIUM | 4.2 | 0.4% | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition |
| CVE-2025-0419 | MEDIUM | 4.7 | 0.2% | Sep 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Infor... |
| CVE-2025-9242 | CRITICAL | 9.8 | 91.1% | Sep 17, 2025 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attac... |
| CVE-2025-9972 | CRITICAL | 9.8 | 2.2% | Sep 17, 2025 | Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability,... |
| CVE-2025-9971 | CRITICAL | 9.8 | 0.8% | Sep 17, 2025 | Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability... |
| CVE-2025-9565 | MEDIUM | 6.4 | 0.2% | Sep 17, 2025 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newslet... |
| CVE-2025-9450 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release... |
| CVE-2025-9449 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS De... |
| CVE-2025-9447 | HIGH | 7.8 | 0.2% | Sep 17, 2025 | An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWOR... |
| CVE-2025-9216 | HIGH | 8.8 | 0.8% | Sep 17, 2025 | The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor... |
| CVE-2025-9215 | MEDIUM | 6.5 | 0.6% | Sep 17, 2025 | The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor... |
| CVE-2025-9203 | MEDIUM | 6.4 | 0.2% | Sep 17, 2025 | The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitl... |
| CVE-2025-10058 | HIGH | 8.1 | 0.6% | Sep 17, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion du... |
| CVE-2025-10057 | HIGH | 8.8 | 0.7% | Sep 17, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in a... |
| CVE-2025-10042 | HIGH | 7.5 | 0.9% | Sep 17, 2025 | The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and inc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now