2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10492 | CRITICAL | 9.8 | 0.9% | Sep 16, 2025 | A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied... |
| CVE-2025-41243 | CRITICAL | 10 | 3.3% | Sep 16, 2025 | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application shoul... |
| CVE-2025-57119 | CRITICAL | 9.8 | 0.5% | Sep 16, 2025 | An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php comp... |
| CVE-2025-55116 | CRITICAL | 9.3 | 0.1% | Sep 16, 2025 | A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the sys... |
| CVE-2025-55115 | CRITICAL | 9.3 | 0.2% | Sep 16, 2025 | A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the syst... |
| CVE-2025-55113 | CRITICAL | 10 | 0.3% | Sep 16, 2025 | If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Cont... |
| CVE-2025-55109 | CRITICAL | 9.5 | 0.3% | Sep 16, 2025 | An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potent... |
| CVE-2025-7744 | CRITICAL | 9.8 | 0.3% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dolusoft Omaspot a... |
| CVE-2025-7743 | CRITICAL | 9.6 | 0.1% | Sep 16, 2025 | Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalat... |
| CVE-2025-4688 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SI... |
| CVE-2025-43362 | CRITICAL | 9.8 | 1.0% | Sep 15, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An ... |
| CVE-2025-43359 | CRITICAL | 9.8 | 0.9% | Sep 15, 2025 | A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and ... |
| CVE-2025-43347 | CRITICAL | 9.8 | 0.8% | Sep 15, 2025 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, t... |
| CVE-2025-43343 | CRITICAL | 9.8 | 0.7% | Sep 15, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tah... |
| CVE-2025-43342 | CRITICAL | 9.8 | 0.7% | Sep 15, 2025 | A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS ... |
| CVE-2025-31255 | CRITICAL | 9.8 | 1.5% | Sep 15, 2025 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS ... |
| CVE-2025-57118 | CRITICAL | 9.8 | 0.5% | Sep 15, 2025 | An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php |
| CVE-2025-10482 | CRITICAL | 9.8 | 0.5% | Sep 15, 2025 | A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio... |
| CVE-2025-10480 | CRITICAL | 9.8 | 0.3% | Sep 15, 2025 | A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown func... |
| CVE-2025-10479 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is... |
| CVE-2025-10477 | CRITICAL | 9.8 | 0.3% | Sep 15, 2025 | A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec... |
| CVE-2025-10473 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the f... |
| CVE-2025-58748 | CRITICAL | 9.8 | 0.8% | Sep 15, 2025 | Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data sou... |
| CVE-2025-57174 | CRITICAL | 9.8 | 1.2% | Sep 15, 2025 | An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and p... |
| CVE-2025-58046 | CRITICAL | 9.8 | 1.3% | Sep 15, 2025 | Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now