2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58276 | MEDIUM | 5.5 | 0.1% | Sep 5, 2025 | Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability ma... |
| CVE-2025-48395 | MEDIUM | 4.7 | 0.3% | Sep 5, 2025 | An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the... |
| CVE-2025-8944 | MEDIUM | 4.3 | 0.2% | Sep 5, 2025 | The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of i... |
| CVE-2025-58400 | HIGH | 8.4 | 0.2% | Sep 5, 2025 | RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted f... |
| CVE-2025-55671 | HIGH | 8.5 | 0.1% | Sep 5, 2025 | Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited... |
| CVE-2025-55037 | CRITICAL | 9.8 | 2.7% | Sep 5, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI ver... |
| CVE-2025-41408 | MEDIUM | 5.3 | 0.3% | Sep 5, 2025 | Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.... |
| CVE-2025-58401 | MEDIUM | 6.8 | 0.1% | Sep 5, 2025 | Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacke... |
| CVE-2025-8684 | MEDIUM | 6.4 | 0.2% | Sep 5, 2025 | The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions... |
| CVE-2025-9990 | HIGH | 8.1 | 0.7% | Sep 5, 2025 | The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and... |
| CVE-2025-7445 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs. |
| CVE-2025-58362 | HIGH | 7.5 | 0.5% | Sep 5, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 conta... |
| CVE-2025-58359 | MEDIUM | 6 | 0.3% | Sep 5, 2025 | ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 th... |
| CVE-2025-58352 | MEDIUM | 6.5 | 0.3% | Sep 5, 2025 | Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session ex... |
| CVE-2025-58179 | MEDIUM | 6.5 | 0.8% | Sep 5, 2025 | Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using A... |
| CVE-2025-55739 | MEDIUM | 5.1 | 0.5% | Sep 5, 2025 | api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower t... |
| CVE-2025-55305 | MEDIUM | 6.1 | 0.3% | Sep 4, 2025 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions belo... |
| CVE-2025-55244 | CRITICAL | 9 | 0.6% | Sep 4, 2025 | Azure Bot Service Elevation of Privilege Vulnerability |
| CVE-2025-55242 | HIGH | 7.5 | 0.7% | Sep 4, 2025 | Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose informati... |
| CVE-2025-55241 | CRITICAL | 10 | 1.5% | Sep 4, 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-55238 | HIGH | 7.5 | 0.8% | Sep 4, 2025 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability |
| CVE-2025-55209 | MEDIUM | 5.1 | 0.3% | Sep 4, 2025 | contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versi... |
| CVE-2025-55190 | CRITICAL | 9.9 | 4.5% | Sep 4, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 thro... |
| CVE-2025-54914 | CRITICAL | 9.8 | 2.2% | Sep 4, 2025 | Azure Networking Elevation of Privilege Vulnerability |
| CVE-2025-58361 | CRITICAL | 9.3 | 0.3% | Sep 4, 2025 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now