2025 CVE Vulnerabilities
45,252 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9696 | CRITICAL | 9.4 | 0.2% | Sep 2, 2025 | The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly a... |
| CVE-2025-55474 | MEDIUM | 6.1 | 0.3% | Sep 2, 2025 | Many Notes 0.10.1 is vulnerable to Cross Site Scripting (XSS), which allows malicious Markdown files to execute JavaScri... |
| CVE-2025-55473 | MEDIUM | 6.1 | 0.3% | Sep 2, 2025 | Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scriptin... |
| CVE-2025-55472 | MEDIUM | 6.5 | 0.3% | Sep 2, 2025 | SQL Injection vulnerability exists in Tirreno v0.9.5, specifically in the /admin/loadUsers API endpoint. The vulnerabili... |
| CVE-2025-55373 | MEDIUM | 5.3 | 0.5% | Sep 2, 2025 | Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to... |
| CVE-2025-57616 | HIGH | 7.5 | 0.3% | Sep 2, 2025 | An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleav... |
| CVE-2025-57615 | HIGH | 7.5 | 0.3% | Sep 2, 2025 | An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new ... |
| CVE-2025-57614 | HIGH | 7.5 | 0.4% | Sep 2, 2025 | An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in t... |
| CVE-2025-57613 | HIGH | 7.5 | 0.3% | Sep 2, 2025 | An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input... |
| CVE-2025-57612 | HIGH | 7.5 | 0.3% | Sep 2, 2025 | An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name() ... |
| CVE-2025-57611 | MEDIUM | 5.3 | 0.3% | Sep 2, 2025 | An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the dump() ... |
| CVE-2025-55372 | MEDIUM | 5.3 | 0.3% | Sep 2, 2025 | An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code vi... |
| CVE-2025-54599 | HIGH | 7.5 | 0.4% | Sep 2, 2025 | The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover,... |
| CVE-2025-50757 | MEDIUM | 6.5 | 1.8% | Sep 2, 2025 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the user... |
| CVE-2025-50755 | MEDIUM | 6.5 | 1.1% | Sep 2, 2025 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the comm... |
| CVE-2025-9784 | HIGH | 7.5 | 2.3% | Sep 2, 2025 | A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering ab... |
| CVE-2025-46047 | MEDIUM | 6.5 | 0.3% | Sep 2, 2025 | A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows... |
| CVE-2025-2413 | HIGH | 8.6 | 0.3% | Sep 2, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypa... |
| CVE-2025-0670 | MEDIUM | 4.7 | 0.2% | Sep 2, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft ProKuafor allows Resource Leak Exposure. Thi... |
| CVE-2025-6519 | CRITICAL | 9.8 | 0.5% | Sep 2, 2025 | E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An at... |
| CVE-2025-5662 | CRITICAL | 9.8 | 0.6% | Sep 2, 2025 | A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3... |
| CVE-2025-57140 | CRITICAL | 9.8 | 0.4% | Sep 2, 2025 | rsbi-pom 4.7 is vulnerable to SQL Injection in the /bi/service/model/DatasetService path. |
| CVE-2025-56254 | MEDIUM | 4.3 | 0.2% | Sep 2, 2025 | PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in lea... |
| CVE-2025-52551 | CRITICAL | 9.3 | 0.3% | Sep 2, 2025 | E2 Facility Management Systems use a proprietary protocol that allows for unauthenticated file operations on any file in... |
| CVE-2025-52550 | HIGH | 7.2 | 0.2% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge ma... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now