2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41035 | MEDIUM | 6.5 | 0.6% | Sep 4, 2025 | A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/dow... |
| CVE-2025-41034 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-41033 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-41032 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-9942 | HIGH | 8.8 | 0.4% | Sep 4, 2025 | A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the fi... |
| CVE-2025-9941 | HIGH | 8.8 | 0.4% | Sep 4, 2025 | A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /regi... |
| CVE-2025-9940 | MEDIUM | 5.4 | 0.3% | Sep 4, 2025 | A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the fil... |
| CVE-2025-9939 | MEDIUM | 5.4 | 0.2% | Sep 4, 2025 | A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an un... |
| CVE-2025-9938 | HIGH | 8.8 | 1.4% | Sep 4, 2025 | A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the ... |
| CVE-2025-9937 | MEDIUM | 5.4 | 0.3% | Sep 4, 2025 | A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalSto... |
| CVE-2025-9936 | MEDIUM | 4.3 | 0.3% | Sep 4, 2025 | A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the f... |
| CVE-2025-9935 | CRITICAL | 9.8 | 3.0% | Sep 4, 2025 | A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_415... |
| CVE-2025-9934 | CRITICAL | 9.8 | 3.7% | Sep 4, 2025 | A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /c... |
| CVE-2025-9933 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknow... |
| CVE-2025-9932 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown f... |
| CVE-2025-9931 | MEDIUM | 6.1 | 0.3% | Sep 4, 2025 | A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!chang... |
| CVE-2025-9930 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown... |
| CVE-2025-9929 | MEDIUM | 4.8 | 0.3% | Sep 4, 2025 | A weakness has been identified in code-projects Responsive Blog Site 1.0. This affects an unknown function of the file b... |
| CVE-2025-9616 | MEDIUM | 5.3 | 0.1% | Sep 4, 2025 | The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. ... |
| CVE-2025-9519 | HIGH | 7.2 | 0.8% | Sep 4, 2025 | The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 v... |
| CVE-2025-9518 | HIGH | 7.2 | 0.9% | Sep 4, 2025 | The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on... |
| CVE-2025-9517 | HIGH | 7.2 | 0.6% | Sep 4, 2025 | The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 ... |
| CVE-2025-9516 | MEDIUM | 4.9 | 0.4% | Sep 4, 2025 | The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 vi... |
| CVE-2025-9467 | MEDIUM | 5.3 | 0.4% | Sep 4, 2025 | When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass ... |
| CVE-2025-6984 | HIGH | 7.5 | 1.5% | Sep 4, 2025 | The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now