2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52389 | HIGH | 8.8 | 0.4% | Sep 8, 2025 | An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attacke... |
| CVE-2025-10104 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown func... |
| CVE-2025-9114 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0.... |
| CVE-2025-9113 | CRITICAL | 9.8 | 0.6% | Sep 8, 2025 | The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the... |
| CVE-2025-9112 | HIGH | 8.8 | 0.5% | Sep 8, 2025 | The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'do... |
| CVE-2025-55849 | HIGH | 8.4 | 0.2% | Sep 8, 2025 | WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee |
| CVE-2025-43722 | MEDIUM | 6.7 | 0.1% | Sep 8, 2025 | Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privi... |
| CVE-2025-10103 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the... |
| CVE-2025-10102 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function o... |
| CVE-2025-57285 | CRITICAL | 9.8 | 2.2% | Sep 8, 2025 | codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync com... |
| CVE-2025-56267 | CRITICAL | 9.8 | 0.7% | Sep 8, 2025 | A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitr... |
| CVE-2025-56266 | CRITICAL | 9.8 | 2.7% | Sep 8, 2025 | A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplyin... |
| CVE-2025-56265 | HIGH | 8.8 | 0.6% | Sep 8, 2025 | An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attac... |
| CVE-2025-10100 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of t... |
| CVE-2025-10099 | MEDIUM | 4.8 | 0.3% | Sep 8, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona... |
| CVE-2025-51586 | LOW | 3.7 | 0.8% | Sep 8, 2025 | An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers ... |
| CVE-2025-10098 | HIGH | 8.8 | 0.4% | Sep 8, 2025 | A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the fil... |
| CVE-2025-10097 | CRITICAL | 9.8 | 0.7% | Sep 8, 2025 | A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app... |
| CVE-2025-10096 | MEDIUM | 6.5 | 0.3% | Sep 8, 2025 | A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app... |
| CVE-2025-7709 | MEDIUM | 6.9 | 0.3% | Sep 8, 2025 | An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of ... |
| CVE-2025-59033 | HIGH | 7.4 | 0.2% | Sep 8, 2025 | The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries... |
| CVE-2025-57141 | CRITICAL | 9.8 | 0.7% | Sep 8, 2025 | rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc. |
| CVE-2025-56630 | HIGH | 7.3 | 0.2% | Sep 8, 2025 | FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Colum... |
| CVE-2025-55998 | HIGH | 8.1 | 0.3% | Sep 8, 2025 | A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacke... |
| CVE-2025-52161 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now