2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57577 | HIGH | 8 | 0.5% | Sep 12, 2025 | An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: t... |
| CVE-2025-55835 | CRITICAL | 9.8 | 0.9% | Sep 12, 2025 | File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filteri... |
| CVE-2025-39799 | — | — | — | Sep 12, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-39798 | MEDIUM | 5.5 | 0.2% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: NFS: Fix the setting of capabilities when automount... |
| CVE-2025-39797 | HIGH | 7.8 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates ... |
| CVE-2025-39796 | HIGH | 7.8 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: lapbether: ignore ops-locked netdevs Syzkalle... |
| CVE-2025-39795 | MEDIUM | 5.5 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: block: avoid possible overflow for chunk_sectors ch... |
| CVE-2025-39794 | MEDIUM | 5.5 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ARM: tegra: Use I/O memcpy to write to IRAM Kasan ... |
| CVE-2025-39793 | HIGH | 7.8 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/memmap: cast nr_pages to size_t before shi... |
| CVE-2025-39792 | MEDIUM | 5.5 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: dm: Always split write BIOs to zoned device limits ... |
| CVE-2025-10320 | LOW | 3.1 | 0.2% | Sep 12, 2025 | A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the f... |
| CVE-2025-55996 | MEDIUM | 6.3 | 0.2% | Sep 12, 2025 | Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface |
| CVE-2025-10319 | MEDIUM | 6.5 | 0.3% | Sep 12, 2025 | A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of th... |
| CVE-2025-9556 | CRITICAL | 9.8 | 0.7% | Sep 12, 2025 | Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5... |
| CVE-2025-59139 | MEDIUM | 5.3 | 0.4% | Sep 12, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw... |
| CVE-2025-59058 | MEDIUM | 5.9 | 0.3% | Sep 12, 2025 | httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signatur... |
| CVE-2025-10365 | CRITICAL | 9.3 | 5.8% | Sep 12, 2025 | The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a w... |
| CVE-2025-10364 | CRITICAL | 9.3 | 6.3% | Sep 12, 2025 | The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a w... |
| CVE-2025-59054 | HIGH | 8.5 | 0.2% | Sep 12, 2025 | dstack is a software development kit (SDK) to simplify the deployment of arbitrary containerized apps into trusted execu... |
| CVE-2025-10318 | HIGH | 8.8 | 0.4% | Sep 12, 2025 | A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of t... |
| CVE-2025-8699 | CRITICAL | 9.1 | 0.7% | Sep 12, 2025 | Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use th... |
| CVE-2025-6638 | HIGH | 7.5 | 0.5% | Sep 12, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp... |
| CVE-2025-27240 | HIGH | 7.2 | 1.2% | Sep 12, 2025 | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visibl... |
| CVE-2025-27238 | LOW | 3.5 | 0.2% | Sep 12, 2025 | Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user gr... |
| CVE-2025-27234 | HIGH | 7.3 | 0.3% | Sep 12, 2025 | Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now