2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8057 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Impro... |
| CVE-2025-57119 | CRITICAL | 9.8 | 0.5% | Sep 16, 2025 | An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php comp... |
| CVE-2025-56276 | MEDIUM | 5.4 | 0.2% | Sep 16, 2025 | code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. ... |
| CVE-2025-52044 | HIGH | 7.5 | 0.4% | Sep 16, 2025 | In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, w... |
| CVE-2025-44034 | HIGH | 8 | 0.5% | Sep 16, 2025 | SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph par... |
| CVE-2025-39836 | HIGH | 7.8 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: efi: stmm: Fix incorrect buffer allocation method ... |
| CVE-2025-39835 | HIGH | 7.8 | 0.2% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: xfs: do not propagate ENODATA disk errors into xatt... |
| CVE-2025-39834 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_action_get_sh... |
| CVE-2025-39833 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitiali... |
| CVE-2025-39832 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix lockdep assertion on sync reset unloa... |
| CVE-2025-39831 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: fbnic: Move phylink resume out of service_task and ... |
| CVE-2025-39830 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_pool_buddy_in... |
| CVE-2025-7355 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Beefull Energy Technologies Beefull App allows Exploit... |
| CVE-2025-55834 | MEDIUM | 6.1 | 0.3% | Sep 16, 2025 | A Cross Site Scripting vulnerability in JeeWMS v.3.7 and before allows a remote attacker to obtain sensitive information... |
| CVE-2025-55118 | HIGH | 8.9 | 0.3% | Sep 16, 2025 | Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issu... |
| CVE-2025-55117 | MEDIUM | 6.3 | 0.3% | Sep 16, 2025 | A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL... |
| CVE-2025-55116 | CRITICAL | 9.3 | 0.1% | Sep 16, 2025 | A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the sys... |
| CVE-2025-55115 | CRITICAL | 9.3 | 0.2% | Sep 16, 2025 | A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the syst... |
| CVE-2025-55114 | MEDIUM | 6.9 | 0.4% | Sep 16, 2025 | The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is vali... |
| CVE-2025-55113 | CRITICAL | 10 | 0.3% | Sep 16, 2025 | If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Cont... |
| CVE-2025-55112 | HIGH | 7.6 | 0.2% | Sep 16, 2025 | Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configu... |
| CVE-2025-55111 | MEDIUM | 5.7 | 0.1% | Sep 16, 2025 | Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 t... |
| CVE-2025-55110 | MEDIUM | 5.7 | 0.1% | Sep 16, 2025 | Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documente... |
| CVE-2025-55109 | CRITICAL | 9.5 | 0.3% | Sep 16, 2025 | An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potent... |
| CVE-2025-39829 | MEDIUM | 5.5 | 0.1% | Sep 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: trace/fgraph: Fix the warning caused by missing unr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now