2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54237 | MEDIUM | 5.5 | 0.2% | Sep 16, 2025 | Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to m... |
| CVE-2025-10572 | — | — | — | Sep 16, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-9199. Reason: This candidate is a r... |
| CVE-2025-59336 | MEDIUM | 6.9 | 0.4% | Sep 16, 2025 | Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of s... |
| CVE-2025-59334 | HIGH | 8.8 | 0.4% | Sep 16, 2025 | Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not v... |
| CVE-2025-59161 | LOW | 2.7 | 0.4% | Sep 16, 2025 | Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11... |
| CVE-2025-59160 | LOW | 2.7 | 0.2% | Sep 16, 2025 | Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insuf... |
| CVE-2025-59050 | HIGH | 7.8 | 0.3% | Sep 16, 2025 | Greenshot is an open source Windows screenshot utility. Greenshot 1.3.300 and earlier deserializes attacker-controlled d... |
| CVE-2025-58174 | MEDIUM | 4.6 | 0.2% | Sep 16, 2025 | LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM before 9.3 allows stor... |
| CVE-2025-43801 | HIGH | 7.5 | 0.4% | Sep 16, 2025 | Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsuppo... |
| CVE-2025-10492 | CRITICAL | 9.8 | 0.9% | Sep 16, 2025 | A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied... |
| CVE-2025-58749 | MEDIUM | 5.3 | 0.3% | Sep 16, 2025 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2... |
| CVE-2025-30075 | LOW | 2.2 | 0.1% | Sep 16, 2025 | In Alludo MindManager before 25.0.208 on Windows, attackers could potentially execute code as other local users on the s... |
| CVE-2025-8894 | HIGH | 7.8 | 0.2% | Sep 16, 2025 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerabi... |
| CVE-2025-8893 | HIGH | 7.8 | 0.2% | Sep 16, 2025 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab... |
| CVE-2025-59333 | HIGH | 8.1 | 0.4% | Sep 16, 2025 | The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-s... |
| CVE-2025-59270 | LOW | 3.1 | 0.2% | Sep 16, 2025 | psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML au... |
| CVE-2025-57145 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The... |
| CVE-2025-56295 | HIGH | 7.3 | 0.3% | Sep 16, 2025 | code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by upload... |
| CVE-2025-56293 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Informat... |
| CVE-2025-56289 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak ad... |
| CVE-2025-56280 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit... |
| CVE-2025-4953 | HIGH | 7.4 | 0.6% | Sep 16, 2025 | A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman... |
| CVE-2025-41243 | CRITICAL | 10 | 3.3% | Sep 16, 2025 | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application shoul... |
| CVE-2025-36244 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local use... |
| CVE-2025-8276 | MEDIUM | 4.3 | 0.3% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now