2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10231 | HIGH | 7.8 | 0.1% | Sep 10, 2025 | An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstanc... |
| CVE-2025-7718 | HIGH | 8.8 | 0.3% | Sep 10, 2025 | The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation ... |
| CVE-2025-10227 | MEDIUM | 4.6 | 0.1% | Sep 10, 2025 | Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2... |
| CVE-2025-10226 | CRITICAL | 9.8 | 0.6% | Sep 10, 2025 | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.... |
| CVE-2025-10225 | HIGH | 8.7 | 0.4% | Sep 10, 2025 | Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in... |
| CVE-2025-10224 | HIGH | 7.1 | 0.3% | Sep 10, 2025 | Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on... |
| CVE-2025-10223 | HIGH | 8.1 | 0.2% | Sep 10, 2025 | Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windo... |
| CVE-2025-10222 | MEDIUM | 4.8 | 0.1% | Sep 10, 2025 | Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon... |
| CVE-2025-10221 | MEDIUM | 6.7 | 0.1% | Sep 10, 2025 | Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet ... |
| CVE-2025-10220 | CRITICAL | 9.8 | 0.7% | Sep 10, 2025 | Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.... |
| CVE-2025-10219 | — | — | — | Sep 10, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-40979 | HIGH | 7 | 0.1% | Sep 10, 2025 | DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this... |
| CVE-2025-40725 | MEDIUM | 5.1 | 0.3% | Sep 10, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute J... |
| CVE-2025-10215 | HIGH | 7.8 | 0.2% | Sep 10, 2025 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc... |
| CVE-2025-10214 | HIGH | 7.8 | 0.2% | Sep 10, 2025 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc... |
| CVE-2025-10213 | HIGH | 7.8 | 0.2% | Sep 10, 2025 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with loc... |
| CVE-2025-36759 | HIGH | 8.7 | 0.3% | Sep 10, 2025 | Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive informa... |
| CVE-2025-36758 | MEDIUM | 6.3 | 0.5% | Sep 10, 2025 | It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Pas... |
| CVE-2025-36757 | MEDIUM | 6.3 | 0.3% | Sep 10, 2025 | It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to byp... |
| CVE-2025-36756 | MEDIUM | 5.8 | 0.3% | Sep 10, 2025 | A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which t... |
| CVE-2025-9979 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missin... |
| CVE-2025-9943 | CRITICAL | 9.1 | 0.4% | Sep 10, 2025 | An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of t... |
| CVE-2025-9888 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2025-9857 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2025-9622 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now