2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27233 | MEDIUM | 5.7 | 0.2% | Sep 12, 2025 | Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex... |
| CVE-2025-10267 | MEDIUM | 6.9 | 0.4% | Sep 12, 2025 | NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote at... |
| CVE-2025-10266 | CRITICAL | 9.8 | 0.5% | Sep 12, 2025 | NUP Pro developed by NewType Infortech has a SQL Injection vulnerability, allowing unauthenticated remote attackers to i... |
| CVE-2025-10265 | HIGH | 8.8 | 1.1% | Sep 12, 2025 | Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote att... |
| CVE-2025-7448 | HIGH | 8.6 | 0.2% | Sep 12, 2025 | Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the ... |
| CVE-2025-10264 | CRITICAL | 10 | 0.4% | Sep 12, 2025 | Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthentic... |
| CVE-2025-21043 | CRITICAL | 9.8 | 1.4% | Sep 12, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitra... |
| CVE-2025-21042 | CRITICAL | 9.8 | 11.6% | Sep 12, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra... |
| CVE-2025-9086 | HIGH | 7.5 | 1.3% | Sep 12, 2025 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak... |
| CVE-2025-8575 | HIGH | 7.2 | 0.7% | Sep 12, 2025 | The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i... |
| CVE-2025-8280 | MEDIUM | 5.8 | 0.2% | Sep 12, 2025 | The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before... |
| CVE-2025-7337 | MEDIUM | 6.5 | 0.4% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3... |
| CVE-2025-6769 | MEDIUM | 4.3 | 0.3% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.... |
| CVE-2025-6454 | HIGH | 8.8 | 0.6% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18... |
| CVE-2025-58781 | MEDIUM | 6.3 | 0.1% | Sep 12, 2025 | WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor en... |
| CVE-2025-3650 | LOW | 3.5 | 0.2% | Sep 12, 2025 | The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes o... |
| CVE-2025-2256 | HIGH | 7.5 | 0.5% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.... |
| CVE-2025-1250 | MEDIUM | 6.5 | 0.4% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.... |
| CVE-2025-10291 | HIGH | 8.8 | 0.3% | Sep 12, 2025 | A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of th... |
| CVE-2025-10148 | MEDIUM | 5.3 | 0.5% | Sep 12, 2025 | curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Ins... |
| CVE-2025-10288 | MEDIUM | 5.5 | 0.5% | Sep 12, 2025 | A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is a... |
| CVE-2025-10287 | LOW | 3.1 | 0.2% | Sep 12, 2025 | A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element... |
| CVE-2025-10094 | MEDIUM | 6.5 | 0.4% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.... |
| CVE-2025-9881 | MEDIUM | 6.1 | 0.1% | Sep 12, 2025 | The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2025-9880 | MEDIUM | 6.1 | 0.1% | Sep 12, 2025 | The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now