2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10662 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /admin_memb... |
| CVE-2025-6237 | CRITICAL | 9.8 | 0.4% | Sep 18, 2025 | A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file del... |
| CVE-2025-9083 | CRITICAL | 9.8 | 0.5% | Sep 18, 2025 | The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticate... |
| CVE-2025-8942 | CRITICAL | 9.1 | 0.3% | Sep 18, 2025 | The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an a... |
| CVE-2025-5305 | CRITICAL | 9.8 | 0.2% | Sep 18, 2025 | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound ... |
| CVE-2025-10624 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A security flaw has been discovered in PHPGurukul User Management System 1.0. This affects an unknown function of the fi... |
| CVE-2025-10623 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown functi... |
| CVE-2025-23316 | CRITICAL | 9.8 | 0.7% | Sep 17, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c... |
| CVE-2025-23268 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker may cause an improper inpu... |
| CVE-2025-10621 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A vulnerability was determined in SourceCodester Hotel Reservation System 1.0. The affected element is an unknown functi... |
| CVE-2025-10644 | CRITICAL | 9.4 | 3.0% | Sep 17, 2025 | Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability a... |
| CVE-2025-10643 | CRITICAL | 9.1 | 2.8% | Sep 17, 2025 | Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remo... |
| CVE-2025-59352 | CRITICAL | 9.8 | 0.7% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and ... |
| CVE-2025-59340 | CRITICAL | 10 | 2.3% | Sep 17, 2025 | jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.... |
| CVE-2025-59345 | CRITICAL | 9.1 | 0.4% | Sep 17, 2025 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs ... |
| CVE-2025-58766 | CRITICAL | 9 | 0.4% | Sep 17, 2025 | Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and ear... |
| CVE-2025-10604 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability was identified in PHPGurukul Online Discussion Forum 1.0. This affects an unknown part of the file /admi... |
| CVE-2025-59304 | CRITICAL | 9.8 | 3.2% | Sep 17, 2025 | A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote... |
| CVE-2025-35434 | CRITICAL | 9.8 | 0.2% | Sep 17, 2025 | CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with acces... |
| CVE-2025-10603 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability was determined in PHPGurukul Online Discussion Forum 1.0. Affected by this issue is some unknown functio... |
| CVE-2025-10601 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. Affected is an unknown function of the... |
| CVE-2025-10600 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /r... |
| CVE-2025-10599 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the... |
| CVE-2025-10598 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This issue affects some unknown p... |
| CVE-2025-10597 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This vuln... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now