2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40930 | HIGH | 7.5 | 0.6% | Sep 8, 2025 | JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing craft... |
| CVE-2025-40929 | MEDIUM | 5.6 | 0.4% | Sep 8, 2025 | Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSO... |
| CVE-2025-40928 | HIGH | 7.5 | 0.6% | Sep 8, 2025 | JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabl... |
| CVE-2025-36855 | HIGH | 8.8 | 0.7% | Sep 8, 2025 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. P... |
| CVE-2025-36854 | HIGH | 8.1 | 0.6% | Sep 8, 2025 | A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream whi... |
| CVE-2025-36853 | HIGH | 7.5 | 0.5% | Sep 8, 2025 | A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: ... |
| CVE-2025-22956 | CRITICAL | 9.8 | 0.3% | Sep 8, 2025 | OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead ... |
| CVE-2025-3212 | MEDIUM | 5.3 | 0.3% | Sep 8, 2025 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2025-40642 | MEDIUM | 5.1 | 0.5% | Sep 8, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in WebWork, which allows remote attackers to execute arbitrary code t... |
| CVE-2025-40641 | MEDIUM | 5.1 | 0.3% | Sep 8, 2025 | Cross-site Scripting (XSS) vulnerability stored in Multi-Purpose Inventory Management System, consisting of a stored XSS... |
| CVE-2025-10093 | HIGH | 7.5 | 0.9% | Sep 8, 2025 | A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi... |
| CVE-2025-10092 | CRITICAL | 9.8 | 0.5% | Sep 8, 2025 | A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectman... |
| CVE-2025-5993 | CRITICAL | 9.2 | 0.6% | Sep 8, 2025 | ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is ab... |
| CVE-2025-10091 | CRITICAL | 9.8 | 0.5% | Sep 8, 2025 | A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.proje... |
| CVE-2025-10090 | CRITICAL | 9.8 | 1.7% | Sep 8, 2025 | A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.dep... |
| CVE-2025-58782 | MEDIUM | 6.5 | 1.3% | Sep 8, 2025 | Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue... |
| CVE-2025-41708 | HIGH | 7.4 | 0.2% | Sep 8, 2025 | Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacke... |
| CVE-2025-41682 | HIGH | 8.8 | 0.3% | Sep 8, 2025 | An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufactu... |
| CVE-2025-41664 | HIGH | 7.5 | 0.2% | Sep 8, 2025 | A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates... |
| CVE-2025-10088 | MEDIUM | 5.4 | 0.3% | Sep 8, 2025 | A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file... |
| CVE-2025-10087 | HIGH | 7.2 | 0.4% | Sep 8, 2025 | A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknow... |
| CVE-2025-8085 | HIGH | 8.6 | 16.4% | Sep 8, 2025 | The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoi... |
| CVE-2025-10086 | MEDIUM | 6.3 | 0.3% | Sep 8, 2025 | A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file ... |
| CVE-2025-10085 | HIGH | 8.8 | 0.3% | Sep 8, 2025 | A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects u... |
| CVE-2025-58422 | LOW | 3.1 | 0.1% | Sep 8, 2025 | RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perfor... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now