2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55162 | HIGH | 8.8 | 0.3% | Sep 3, 2025 | Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In vers... |
| CVE-2025-53690 | CRITICAL | 9 | 26.3% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a... |
| CVE-2025-9924 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of... |
| CVE-2025-9923 | MEDIUM | 6.1 | 0.4% | Sep 3, 2025 | A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. ... |
| CVE-2025-36193 | MEDIUM | 6.7 | 0.1% | Sep 3, 2025 | IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could all... |
| CVE-2025-56803 | HIGH | 8.4 | 1.1% | Sep 3, 2025 | Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An atta... |
| CVE-2025-56752 | CRITICAL | 9.4 | 0.5% | Sep 3, 2025 | A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass auth... |
| CVE-2025-52494 | HIGH | 7.5 | 0.3% | Sep 3, 2025 | Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling o... |
| CVE-2025-45805 | HIGH | 7.6 | 0.4% | Sep 3, 2025 | In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript cod... |
| CVE-2025-20336 | HIGH | 7.5 | 0.3% | Sep 3, 2025 | A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C... |
| CVE-2025-20335 | MEDIUM | 5.3 | 0.3% | Sep 3, 2025 | A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and C... |
| CVE-2025-20330 | MEDIUM | 6.1 | 0.2% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service ... |
| CVE-2025-20328 | MEDIUM | 5.4 | 0.2% | Sep 3, 2025 | A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attack... |
| CVE-2025-20326 | HIGH | 8.8 | 0.2% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and ... |
| CVE-2025-20291 | MEDIUM | 6.1 | 0.2% | Sep 3, 2025 | A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted We... |
| CVE-2025-20287 | HIGH | 8.8 | 0.3% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a... |
| CVE-2025-20280 | MEDIUM | 4.8 | 0.2% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2025-20270 | MEDIUM | 6.5 | 0.3% | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2025-9959 | HIGH | 7.6 | 0.3% | Sep 3, 2025 | Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sand... |
| CVE-2025-9922 | MEDIUM | 6.1 | 0.4% | Sep 3, 2025 | A security vulnerability has been detected in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability i... |
| CVE-2025-9921 | MEDIUM | 5.4 | 0.3% | Sep 3, 2025 | A weakness has been identified in code-projects POS Pharmacy System 1.0. Affected is an unknown function of the file /ma... |
| CVE-2025-9867 | MEDIUM | 5.4 | 0.3% | Sep 3, 2025 | Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker t... |
| CVE-2025-9866 | HIGH | 8.8 | 0.4% | Sep 3, 2025 | Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass c... |
| CVE-2025-9865 | MEDIUM | 5.4 | 0.2% | Sep 3, 2025 | Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who... |
| CVE-2025-9864 | — | — | — | Sep 3, 2025 | Rejected reason: This CVE ID was assigned in error to a vulnerability that was both introduced and fixed before the code... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now