2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59827 | CRITICAL | 9.8 | 0.3% | Sep 24, 2025 | Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper acc... |
| CVE-2025-59828 | CRITICAL | 9.8 | 0.3% | Sep 24, 2025 | Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.... |
| CVE-2025-57321 | CRITICAL | 9.8 | 0.4% | Sep 24, 2025 | A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 all... |
| CVE-2025-57347 | CRITICAL | 9.8 | 0.5% | Sep 24, 2025 | A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConf... |
| CVE-2025-52906 | CRITICAL | 9.8 | 13.2% | Sep 24, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60... |
| CVE-2025-10890 | CRITICAL | 9.1 | 0.3% | Sep 24, 2025 | Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-... |
| CVE-2025-10585 | CRITICAL | 9.8 | 5.4% | Sep 24, 2025 | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2025-56819 | CRITICAL | 9.8 | 3.0% | Sep 24, 2025 | An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter. |
| CVE-2025-27034 | CRITICAL | 9.8 | 0.4% | Sep 24, 2025 | Memory corruption while selecting the PLMN from SOR failed list. |
| CVE-2025-21483 | CRITICAL | 9.8 | 0.4% | Sep 24, 2025 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. |
| CVE-2025-9054 | CRITICAL | 9.8 | 0.3% | Sep 24, 2025 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi... |
| CVE-2025-41715 | CRITICAL | 9.8 | 0.5% | Sep 24, 2025 | The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to g... |
| CVE-2025-59545 | CRITICAL | 9 | 0.5% | Sep 23, 2025 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
| CVE-2025-4993 | CRITICAL | 9.1 | 0.3% | Sep 23, 2025 | Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.Thi... |
| CVE-2025-1255 | CRITICAL | 9.1 | 0.3% | Sep 23, 2025 | Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.Thi... |
| CVE-2025-9846 | CRITICAL | 10 | 1.0% | Sep 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry In... |
| CVE-2025-9965 | CRITICAL | 9.3 | 0.7% | Sep 23, 2025 | Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any ap... |
| CVE-2025-9963 | CRITICAL | 9.4 | 0.2% | Sep 23, 2025 | A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with r... |
| CVE-2025-9962 | CRITICAL | 10 | 1.4% | Sep 23, 2025 | A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without prior authenticatio... |
| CVE-2025-10412 | CRITICAL | 9.8 | 0.6% | Sep 23, 2025 | The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl... |
| CVE-2025-10857 | CRITICAL | 9.8 | 0.5% | Sep 23, 2025 | A security flaw has been discovered in Campcodes Point of Sale System POS 1.0. Affected by this issue is some unknown fu... |
| CVE-2025-10147 | CRITICAL | 9.8 | 0.9% | Sep 23, 2025 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali... |
| CVE-2025-9588 | CRITICAL | 9.8 | 1.1% | Sep 23, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountai... |
| CVE-2025-10851 | CRITICAL | 9.8 | 0.4% | Sep 23, 2025 | A security flaw has been discovered in Campcodes Gym Management System 1.0. Impacted is an unknown function of the file ... |
| CVE-2025-10843 | CRITICAL | 9.8 | 0.4% | Sep 23, 2025 | A flaw has been found in Reservation Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now