2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59934 | CRITICAL | 9.4 | 8.0% | Sep 26, 2025 | Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verifica... |
| CVE-2025-11046 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /... |
| CVE-2025-11040 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A vulnerability was detected in code-projects Hostel Management System 1.0. Affected by this issue is some unknown funct... |
| CVE-2025-11039 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. Affected by this vulner... |
| CVE-2025-11037 | CRITICAL | 9.8 | 0.5% | Sep 26, 2025 | A security flaw has been discovered in code-projects E-Commerce Website 1.0. This impacts an unknown function of the fil... |
| CVE-2025-11036 | CRITICAL | 9.8 | 0.5% | Sep 26, 2025 | A vulnerability was identified in code-projects E-Commerce Website 1.0. This affects an unknown function of the file /pa... |
| CVE-2025-11035 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.... |
| CVE-2025-58384 | CRITICAL | 10 | 0.7% | Sep 26, 2025 | In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .... |
| CVE-2025-11033 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted ... |
| CVE-2025-11032 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A flaw has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This issue affects... |
| CVE-2025-55187 | CRITICAL | 9.9 | 0.4% | Sep 26, 2025 | In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privilege... |
| CVE-2025-9642 | CRITICAL | 9.6 | 0.5% | Sep 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18... |
| CVE-2025-60219 | CRITICAL | 10 | 0.4% | Sep 26, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allo... |
| CVE-2025-60156 | CRITICAL | 9.6 | 0.2% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web She... |
| CVE-2025-11005 | CRITICAL | 9.8 | 1.3% | Sep 25, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60... |
| CVE-2025-59841 | CRITICAL | 9.8 | 0.4% | Sep 25, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application i... |
| CVE-2025-20363 | CRITICAL | 9 | 7.5% | Sep 25, 2025 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Fi... |
| CVE-2025-20333 | CRITICAL | 9.9 | 40.4% | Sep 25, 2025 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu... |
| CVE-2025-59832 | CRITICAL | 9.9 | 0.4% | Sep 25, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS... |
| CVE-2025-59823 | CRITICAL | 9.9 | 0.5% | Sep 25, 2025 | Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection m... |
| CVE-2025-40836 | CRITICAL | 9.8 | 0.4% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacke... |
| CVE-2025-10542 | CRITICAL | 9.8 | 0.7% | Sep 25, 2025 | iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s... |
| CVE-2025-59834 | CRITICAL | 9.8 | 2.3% | Sep 25, 2025 | ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.... |
| CVE-2025-27261 | CRITICAL | 9.8 | 0.3% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized discl... |
| CVE-2025-10894 | CRITICAL | 9.6 | 0.5% | Sep 24, 2025 | Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was pub... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now