2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58751 | MEDIUM | 5.3 | 1.2% | Sep 8, 2025 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting w... |
| CVE-2025-58746 | CRITICAL | 9 | 0.3% | Sep 8, 2025 | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashbo... |
| CVE-2025-58745 | HIGH | 8.8 | 0.7% | Sep 8, 2025 | WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary... |
| CVE-2025-58454 | HIGH | 8.2 | 0.3% | Sep 8, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1... |
| CVE-2025-58453 | HIGH | 8.2 | 0.3% | Sep 8, 2025 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1... |
| CVE-2025-58452 | MEDIUM | 6.1 | 0.2% | Sep 8, 2025 | WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-1761 | HIGH | 7.5 | 0.3% | Sep 8, 2025 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me... |
| CVE-2025-10111 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a... |
| CVE-2025-10110 | HIGH | 8.8 | 0.3% | Sep 8, 2025 | A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipul... |
| CVE-2025-10109 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processin... |
| CVE-2025-58451 | HIGH | 8.7 | 0.3% | Sep 8, 2025 | Cattown is a JavaScript markdown parser. Versions prior to 1.0.2 used regular expressions with inefficient, potentially ... |
| CVE-2025-58450 | CRITICAL | 9.3 | 0.3% | Sep 8, 2025 | pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible... |
| CVE-2025-58449 | HIGH | 8.7 | 0.3% | Sep 8, 2025 | Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to t... |
| CVE-2025-58444 | HIGH | 8.6 | 0.6% | Sep 8, 2025 | The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported i... |
| CVE-2025-58365 | HIGH | 8.7 | 0.5% | Sep 8, 2025 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Prior to version 9.14, th... |
| CVE-2025-57817 | HIGH | 7.2 | 0.4% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endp... |
| CVE-2025-57816 | HIGH | 7.5 | 0.4% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-bas... |
| CVE-2025-57815 | MEDIUM | 6.5 | 0.3% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies ... |
| CVE-2025-57766 | MEDIUM | 4.8 | 0.3% | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides d... |
| CVE-2025-10108 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the... |
| CVE-2025-10106 | HIGH | 8.8 | 0.4% | Sep 8, 2025 | A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collec... |
| CVE-2025-52288 | HIGH | 7.5 | 0.4% | Sep 8, 2025 | Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Ma... |
| CVE-2025-10105 | HIGH | 8.8 | 0.3% | Sep 8, 2025 | A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the f... |
| CVE-2025-54994 | CRITICAL | 9.3 | 1.4% | Sep 8, 2025 | @akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13... |
| CVE-2025-53838 | MEDIUM | 5.4 | 0.2% | Sep 8, 2025 | LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discove... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now