2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59304 | CRITICAL | 9.8 | 3.2% | Sep 17, 2025 | A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote... |
| CVE-2025-35434 | CRITICAL | 9.8 | 0.2% | Sep 17, 2025 | CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with acces... |
| CVE-2025-10603 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability was determined in PHPGurukul Online Discussion Forum 1.0. Affected by this issue is some unknown functio... |
| CVE-2025-10601 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. Affected is an unknown function of the... |
| CVE-2025-10600 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /r... |
| CVE-2025-10599 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the... |
| CVE-2025-10598 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This issue affects some unknown p... |
| CVE-2025-10597 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This vuln... |
| CVE-2025-10596 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /i... |
| CVE-2025-8077 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default pass... |
| CVE-2025-10439 | CRITICAL | 9.8 | 0.3% | Sep 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics... |
| CVE-2025-10156 | CRITICAL | 9.8 | 1.4% | Sep 17, 2025 | An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 pickles... |
| CVE-2025-59458 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54... |
| CVE-2025-9242 | CRITICAL | 9.8 | 91.1% | Sep 17, 2025 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attac... |
| CVE-2025-9972 | CRITICAL | 9.8 | 2.2% | Sep 17, 2025 | Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability,... |
| CVE-2025-9971 | CRITICAL | 9.8 | 0.8% | Sep 17, 2025 | Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability... |
| CVE-2025-54391 | CRITICAL | 9.1 | 0.6% | Sep 16, 2025 | A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with va... |
| CVE-2025-10565 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. Affected by this vulnerability is an... |
| CVE-2025-10564 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the fi... |
| CVE-2025-57631 | CRITICAL | 9.8 | 0.8% | Sep 16, 2025 | SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file up... |
| CVE-2025-34186 | CRITICAL | 9.8 | 0.8% | Sep 16, 2025 | Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized in... |
| CVE-2025-34184 | CRITICAL | 9.8 | 2.8% | Sep 16, 2025 | Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax... |
| CVE-2025-10563 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of ... |
| CVE-2025-56557 | CRITICAL | 9.1 | 0.3% | Sep 16, 2025 | An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Mat... |
| CVE-2025-10562 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now