2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11033 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted ... |
| CVE-2025-11032 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A flaw has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This issue affects... |
| CVE-2025-55187 | CRITICAL | 9.9 | 0.4% | Sep 26, 2025 | In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privilege... |
| CVE-2025-9642 | CRITICAL | 9.6 | 0.5% | Sep 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18... |
| CVE-2025-60219 | CRITICAL | 10 | 0.4% | Sep 26, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allo... |
| CVE-2025-60156 | CRITICAL | 9.6 | 0.2% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web She... |
| CVE-2025-11005 | CRITICAL | 9.8 | 1.3% | Sep 25, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60... |
| CVE-2025-59841 | CRITICAL | 9.8 | 0.4% | Sep 25, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application i... |
| CVE-2025-20363 | CRITICAL | 9 | 7.5% | Sep 25, 2025 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Fi... |
| CVE-2025-20333 | CRITICAL | 9.9 | 40.4% | Sep 25, 2025 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu... |
| CVE-2025-59832 | CRITICAL | 9.9 | 0.4% | Sep 25, 2025 | Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS... |
| CVE-2025-59823 | CRITICAL | 9.9 | 0.5% | Sep 25, 2025 | Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection m... |
| CVE-2025-40836 | CRITICAL | 9.8 | 0.4% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacke... |
| CVE-2025-10542 | CRITICAL | 9.8 | 0.7% | Sep 25, 2025 | iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s... |
| CVE-2025-59834 | CRITICAL | 9.8 | 2.3% | Sep 25, 2025 | ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.... |
| CVE-2025-27261 | CRITICAL | 9.8 | 0.3% | Sep 25, 2025 | Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized discl... |
| CVE-2025-10894 | CRITICAL | 9.6 | 0.5% | Sep 24, 2025 | Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was pub... |
| CVE-2025-59827 | CRITICAL | 9.8 | 0.3% | Sep 24, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper acc... |
| CVE-2025-59828 | CRITICAL | 9.8 | 0.3% | Sep 24, 2025 | Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.... |
| CVE-2025-57321 | CRITICAL | 9.8 | 0.4% | Sep 24, 2025 | A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 all... |
| CVE-2025-57347 | CRITICAL | 9.8 | 0.5% | Sep 24, 2025 | A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConf... |
| CVE-2025-52906 | CRITICAL | 9.8 | 13.2% | Sep 24, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60... |
| CVE-2025-10890 | CRITICAL | 9.1 | 0.3% | Sep 24, 2025 | Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-... |
| CVE-2025-10585 | CRITICAL | 9.8 | 5.4% | Sep 24, 2025 | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2025-56819 | CRITICAL | 9.8 | 3.0% | Sep 24, 2025 | An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now