2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36082 | LOW | 3.3 | 0.1% | Sep 15, 2025 | IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system. |
| CVE-2025-10491 | HIGH | 7.8 | 0.1% | Sep 15, 2025 | The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker t... |
| CVE-2025-8396 | MEDIUM | 6.9 | 0.4% | Sep 15, 2025 | Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server o... |
| CVE-2025-6202 | HIGH | 7.1 | 0.3% | Sep 15, 2025 | Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Inte... |
| CVE-2025-52053 | CRITICAL | 9.8 | 4.4% | Sep 15, 2025 | TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 functio... |
| CVE-2025-10459 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of ... |
| CVE-2025-59377 | CRITICAL | 9.8 | 1.2% | Sep 15, 2025 | feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl beca... |
| CVE-2025-59376 | MEDIUM | 5.3 | 0.3% | Sep 15, 2025 | feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-writ... |
| CVE-2025-56710 | HIGH | 7.3 | 0.2% | Sep 15, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Ma... |
| CVE-2025-50944 | HIGH | 8.8 | 0.2% | Sep 15, 2025 | An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes ... |
| CVE-2025-50110 | HIGH | 8.8 | 0.2% | Sep 15, 2025 | An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, th... |
| CVE-2025-46408 | CRITICAL | 9.8 | 0.6% | Sep 15, 2025 | An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_Htt... |
| CVE-2025-10448 | CRITICAL | 9.8 | 0.5% | Sep 15, 2025 | A flaw has been found in Campcodes Online Job Finder System 1.0. This affects an unknown function of the file /index.php... |
| CVE-2025-10447 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of t... |
| CVE-2025-3025 | HIGH | 7.3 | 0.1% | Sep 15, 2025 | Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local use... |
| CVE-2025-39804 | HIGH | 7.8 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm64/poly1305: Fix register corruption... |
| CVE-2025-39803 | HIGH | 7.8 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove WARN_ON_ONCE() call from uf... |
| CVE-2025-39802 | HIGH | 7.8 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm/poly1305: Fix register corruption i... |
| CVE-2025-39801 | MEDIUM | 5.5 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint comma... |
| CVE-2025-39800 | MEDIUM | 5.5 | 0.1% | Sep 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on unexpected eb generatio... |
| CVE-2025-10446 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. The affected element is... |
| CVE-2025-10445 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of ... |
| CVE-2025-59361 | CRITICAL | 9.8 | 3.3% | Sep 15, 2025 | The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20... |
| CVE-2025-59360 | CRITICAL | 9.8 | 2.8% | Sep 15, 2025 | The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20... |
| CVE-2025-59359 | CRITICAL | 9.8 | 2.9% | Sep 15, 2025 | The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now