2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53694 | HIGH | 7.5 | 5.3% | Sep 3, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), S... |
| CVE-2025-53693 | CRITICAL | 9.8 | 13.8% | Sep 3, 2025 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Ex... |
| CVE-2025-53691 | HIGH | 8.8 | 1.4% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a... |
| CVE-2025-3701 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner wp-malware-removal allows Exploiting... |
| CVE-2025-38678 | MEDIUM | 5.5 | 0.2% | Sep 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject duplicate device on up... |
| CVE-2025-41000 | LOW | 2.1 | 0.3% | Sep 3, 2025 | Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits... |
| CVE-2025-9821 | LOW | 2.7 | 0.3% | Sep 3, 2025 | SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, t... |
| CVE-2025-9219 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo,... |
| CVE-2025-2415 | HIGH | 8.6 | 0.3% | Sep 3, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas... |
| CVE-2025-1740 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas... |
| CVE-2025-9817 | HIGH | 7.5 | 0.2% | Sep 3, 2025 | SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service |
| CVE-2025-9378 | MEDIUM | 6.4 | 0.2% | Sep 3, 2025 | The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-8663 | MEDIUM | 6.5 | 0.3% | Sep 3, 2025 | Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know... |
| CVE-2025-58210 | CRITICAL | 9.8 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in ThemeMove Makeaholic makeaholic allows Exploiting Incorrectly Configured Access C... |
| CVE-2025-58272 | LOW | 3.7 | 0.1% | Sep 3, 2025 | Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views ... |
| CVE-2025-21041 | MEDIUM | 5.5 | 0.1% | Sep 3, 2025 | Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitiv... |
| CVE-2025-21040 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attacker... |
| CVE-2025-21039 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local... |
| CVE-2025-21038 | LOW | 3.3 | 0.1% | Sep 3, 2025 | Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows loca... |
| CVE-2025-21037 | MEDIUM | 4.3 | 0.1% | Sep 3, 2025 | Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across mult... |
| CVE-2025-21036 | MEDIUM | 5 | 0.1% | Sep 3, 2025 | Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported... |
| CVE-2025-21035 | MEDIUM | 4.6 | 0.2% | Sep 3, 2025 | Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows... |
| CVE-2025-21034 | HIGH | 7.8 | 0.1% | Sep 3, 2025 | Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitr... |
| CVE-2025-21033 | MEDIUM | 5.5 | 0.1% | Sep 3, 2025 | Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive in... |
| CVE-2025-21032 | MEDIUM | 6.8 | 0.2% | Sep 3, 2025 | Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode un... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now