2025 CVE Vulnerabilities
45,252 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52549 | CRITICAL | 9.8 | 0.5% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can ... |
| CVE-2025-52548 | MEDIUM | 4.9 | 0.3% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enab... |
| CVE-2025-52547 | HIGH | 7.5 | 0.3% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacke... |
| CVE-2025-52546 | MEDIUM | 6.1 | 0.2% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta... |
| CVE-2025-52545 | HIGH | 7.5 | 0.2% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which retur... |
| CVE-2025-52544 | HIGH | 7.5 | 0.3% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta... |
| CVE-2025-52543 | HIGH | 7.5 | 0.3% | Sep 2, 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for ... |
| CVE-2025-46810 | HIGH | 8.5 | 0.1% | Sep 2, 2025 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traef... |
| CVE-2025-2414 | HIGH | 8.6 | 0.3% | Sep 2, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypa... |
| CVE-2025-0640 | MEDIUM | 4.7 | 0.2% | Sep 2, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft OctoCloud allows Resource Leak Exposure. Thi... |
| CVE-2025-9573 | HIGH | 8.6 | 1.1% | Sep 2, 2025 | The ns_backup extension through 13.0.2 for TYPO3 allows command injection. |
| CVE-2025-41031 | MEDIUM | 6.9 | 0.3% | Sep 2, 2025 | Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other us... |
| CVE-2025-41030 | MEDIUM | 6.9 | 0.3% | Sep 2, 2025 | Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain informat... |
| CVE-2025-44017 | MEDIUM | 5.1 | 0.2% | Sep 2, 2025 | "Gunosy" App contains a vulnerability where sensitive information may be included in the application's outbound communic... |
| CVE-2025-41690 | HIGH | 7.4 | 0.2% | Sep 2, 2025 | A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance)... |
| CVE-2025-9815 | HIGH | 7.8 | 0.3% | Sep 2, 2025 | A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function o... |
| CVE-2025-9814 | CRITICAL | 9.8 | 0.4% | Sep 2, 2025 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function ... |
| CVE-2025-9813 | HIGH | 8.8 | 0.8% | Sep 2, 2025 | A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /gofo... |
| CVE-2025-9812 | HIGH | 8.8 | 0.6% | Sep 2, 2025 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file... |
| CVE-2025-9811 | CRITICAL | 9.8 | 0.4% | Sep 2, 2025 | A vulnerability was found in Campcodes Farm Management System 1.0. This affects an unknown part of the file /reviewInput... |
| CVE-2025-8662 | MEDIUM | 4.3 | 0.3% | Sep 2, 2025 | OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tamp... |
| CVE-2025-58421 | — | — | — | Sep 2, 2025 | Rejected reason: Not used |
| CVE-2025-58420 | — | — | — | Sep 2, 2025 | Rejected reason: Not used |
| CVE-2025-58419 | — | — | — | Sep 2, 2025 | Rejected reason: Not used |
| CVE-2025-58418 | — | — | — | Sep 2, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now