2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10596 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /i... |
| CVE-2025-8077 | CRITICAL | 9.8 | 0.5% | Sep 17, 2025 | A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default pass... |
| CVE-2025-10439 | CRITICAL | 9.8 | 0.3% | Sep 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics... |
| CVE-2025-10156 | CRITICAL | 9.8 | 1.5% | Sep 17, 2025 | An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 pickles... |
| CVE-2025-59458 | CRITICAL | 9.8 | 0.4% | Sep 17, 2025 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54... |
| CVE-2025-9242 | CRITICAL | 9.8 | 91.1% | Sep 17, 2025 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attac... |
| CVE-2025-9972 | CRITICAL | 9.8 | 2.2% | Sep 17, 2025 | Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability,... |
| CVE-2025-9971 | CRITICAL | 9.8 | 0.8% | Sep 17, 2025 | Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability... |
| CVE-2025-54391 | CRITICAL | 9.1 | 0.6% | Sep 16, 2025 | A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with va... |
| CVE-2025-10565 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. Affected by this vulnerability is an... |
| CVE-2025-10564 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the fi... |
| CVE-2025-57631 | CRITICAL | 9.8 | 0.8% | Sep 16, 2025 | SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file up... |
| CVE-2025-34186 | CRITICAL | 9.8 | 0.8% | Sep 16, 2025 | Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized in... |
| CVE-2025-34184 | CRITICAL | 9.8 | 2.8% | Sep 16, 2025 | Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax... |
| CVE-2025-10563 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of ... |
| CVE-2025-56557 | CRITICAL | 9.1 | 0.3% | Sep 16, 2025 | An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Mat... |
| CVE-2025-10562 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file ... |
| CVE-2025-10492 | CRITICAL | 9.8 | 0.9% | Sep 16, 2025 | A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied... |
| CVE-2025-41243 | CRITICAL | 10 | 3.3% | Sep 16, 2025 | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application shoul... |
| CVE-2025-57119 | CRITICAL | 9.8 | 0.5% | Sep 16, 2025 | An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php comp... |
| CVE-2025-55116 | CRITICAL | 9.3 | 0.1% | Sep 16, 2025 | A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the sys... |
| CVE-2025-55115 | CRITICAL | 9.3 | 0.2% | Sep 16, 2025 | A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the syst... |
| CVE-2025-55113 | CRITICAL | 10 | 0.3% | Sep 16, 2025 | If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Cont... |
| CVE-2025-55109 | CRITICAL | 9.5 | 0.3% | Sep 16, 2025 | An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potent... |
| CVE-2025-7744 | CRITICAL | 9.8 | 0.3% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dolusoft Omaspot a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now