2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10769 | CRITICAL | 9.8 | 0.5% | Sep 21, 2025 | A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLT... |
| CVE-2025-10768 | CRITICAL | 9.8 | 0.4% | Sep 21, 2025 | A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQ... |
| CVE-2025-6544 | CRITICAL | 9.8 | 0.8% | Sep 21, 2025 | A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system ... |
| CVE-2025-40925 | CRITICAL | 9.1 | 0.3% | Sep 20, 2025 | Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash... |
| CVE-2025-59431 | CRITICAL | 9.8 | 0.4% | Sep 19, 2025 | MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive Property... |
| CVE-2025-10568 | CRITICAL | 9.8 | 0.3% | Sep 19, 2025 | HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to addr... |
| CVE-2025-34206 | CRITICAL | 9.8 | 0.5% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configu... |
| CVE-2025-34205 | CRITICAL | 9.8 | 1.3% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.192... |
| CVE-2025-34204 | CRITICAL | 9.8 | 0.6% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple ... |
| CVE-2025-34203 | CRITICAL | 9.8 | 0.8% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior t... |
| CVE-2025-34198 | CRITICAL | 9.8 | 0.7% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.236... |
| CVE-2025-34195 | CRITICAL | 9.8 | 0.9% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330... |
| CVE-2025-34193 | CRITICAL | 9.8 | 0.7% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to... |
| CVE-2025-34192 | CRITICAL | 9.8 | 0.9% | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to... |
| CVE-2025-48703 | CRITICAL | 9 | 99.6% | Sep 19, 2025 | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell... |
| CVE-2025-57644 | CRITICAL | 9.1 | 0.7% | Sep 19, 2025 | Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticate... |
| CVE-2025-5948 | CRITICAL | 9.8 | 0.4% | Sep 19, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2025-59717 | CRITICAL | 9.8 | 0.4% | Sep 19, 2025 | In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .i... |
| CVE-2025-10690 | CRITICAL | 9.8 | 0.7% | Sep 19, 2025 | The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads du... |
| CVE-2025-10035 | CRITICAL | 9.8 | 99.6% | Sep 18, 2025 | A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged ... |
| CVE-2025-54807 | CRITICAL | 9.8 | 0.7% | Sep 18, 2025 | The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker... |
| CVE-2025-30519 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standa... |
| CVE-2025-10689 | CRITICAL | 9.8 | 4.6% | Sep 18, 2025 | A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.... |
| CVE-2025-10688 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow... |
| CVE-2025-10687 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability was found in SourceCodester Responsive E-Learning System 1.0. This affects an unknown part of the file /... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now