2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59034 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior t... |
| CVE-2025-58764 | CRITICAL | 9.8 | 0.5% | Sep 10, 2025 | Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to ... |
| CVE-2025-57573 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi... |
| CVE-2025-57572 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentC... |
| CVE-2025-57571 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT... |
| CVE-2025-57570 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS. |
| CVE-2025-57569 | MEDIUM | 5.6 | 0.2% | Sep 10, 2025 | Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT. |
| CVE-2025-43938 | MEDIUM | 4.4 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnera... |
| CVE-2025-43888 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information in... |
| CVE-2025-43887 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerab... |
| CVE-2025-43886 | MEDIUM | 4.4 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerabili... |
| CVE-2025-43885 | HIGH | 7.8 | 0.5% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Ele... |
| CVE-2025-43884 | MEDIUM | 6.7 | 0.5% | Sep 10, 2025 | Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Ele... |
| CVE-2025-43725 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default P... |
| CVE-2025-29592 | MEDIUM | 5.6 | 0.4% | Sep 10, 2025 | oasys v1.1 is vulnerable to Directory Traversal in ProcedureController. |
| CVE-2025-20340 | HIGH | 7.4 | 0.6% | Sep 10, 2025 | A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthen... |
| CVE-2025-20248 | MEDIUM | 6 | 0.1% | Sep 10, 2025 | A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to byp... |
| CVE-2025-20159 | MEDIUM | 5.3 | 0.3% | Sep 10, 2025 | A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could ... |
| CVE-2025-56578 | MEDIUM | 5.7 | 0.3% | Sep 10, 2025 | An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the... |
| CVE-2025-56466 | HIGH | 7.5 | 0.3% | Sep 10, 2025 | Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information. |
| CVE-2025-56413 | HIGH | 8.8 | 1.2% | Sep 10, 2025 | OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary comman... |
| CVE-2025-56407 | HIGH | 8.8 | 0.3% | Sep 10, 2025 | A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function ... |
| CVE-2025-56406 | HIGH | 7.5 | 0.4% | Sep 10, 2025 | An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary comma... |
| CVE-2025-56405 | HIGH | 7.5 | 0.3% | Sep 10, 2025 | An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the ... |
| CVE-2025-56404 | HIGH | 7.5 | 0.3% | Sep 10, 2025 | An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now