2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6085 | HIGH | 7.2 | 1.2% | Sep 4, 2025 | The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validatio... |
| CVE-2025-58701 | — | — | — | Sep 4, 2025 | Rejected reason: Not used |
| CVE-2025-58700 | — | — | — | Sep 4, 2025 | Rejected reason: Not used |
| CVE-2025-58699 | — | — | — | Sep 4, 2025 | Rejected reason: Not used |
| CVE-2025-58698 | — | — | — | Sep 4, 2025 | Rejected reason: Not used |
| CVE-2025-58697 | — | — | — | Sep 4, 2025 | Rejected reason: Not used |
| CVE-2025-58696 | — | — | — | Sep 4, 2025 | Rejected reason: Not used |
| CVE-2025-58695 | — | — | — | Sep 4, 2025 | Rejected reason: Not used |
| CVE-2025-58694 | — | — | — | Sep 4, 2025 | Rejected reason: Not used |
| CVE-2025-58358 | HIGH | 7.5 | 1.0% | Sep 4, 2025 | Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain ... |
| CVE-2025-58357 | CRITICAL | 9.6 | 0.6% | Sep 4, 2025 | 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 con... |
| CVE-2025-58355 | HIGH | 7.7 | 0.3% | Sep 4, 2025 | Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or over... |
| CVE-2025-58171 | — | — | — | Sep 4, 2025 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2025-58064 | LOW | 2.3 | 0.4% | Sep 4, 2025 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions ... |
| CVE-2025-58057 | HIGH | 7.5 | 0.6% | Sep 4, 2025 | Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan... |
| CVE-2025-43772 | HIGH | 7.1 | 0.5% | Sep 4, 2025 | Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older u... |
| CVE-2025-36909 | MEDIUM | 5.3 | 0.1% | Sep 4, 2025 | Information disclosure |
| CVE-2025-36908 | MEDIUM | 6.7 | 0.1% | Sep 4, 2025 | In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. ... |
| CVE-2025-36907 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer ove... |
| CVE-2025-36906 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer ov... |
| CVE-2025-36905 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This ... |
| CVE-2025-36904 | CRITICAL | 9.8 | 0.2% | Sep 4, 2025 | WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384. |
| CVE-2025-36903 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local e... |
| CVE-2025-36902 | MEDIUM | 6.7 | 0.1% | Sep 4, 2025 | In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overfl... |
| CVE-2025-36901 | HIGH | 8.8 | 0.1% | Sep 4, 2025 | WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now