2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7743 | CRITICAL | 9.6 | 0.1% | Sep 16, 2025 | Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalat... |
| CVE-2025-4688 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SI... |
| CVE-2025-43362 | CRITICAL | 9.8 | 1.0% | Sep 15, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An ... |
| CVE-2025-43359 | CRITICAL | 9.8 | 0.9% | Sep 15, 2025 | A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and ... |
| CVE-2025-43347 | CRITICAL | 9.8 | 0.8% | Sep 15, 2025 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, t... |
| CVE-2025-43343 | CRITICAL | 9.8 | 0.7% | Sep 15, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tah... |
| CVE-2025-43342 | CRITICAL | 9.8 | 0.7% | Sep 15, 2025 | A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS ... |
| CVE-2025-31255 | CRITICAL | 9.8 | 1.5% | Sep 15, 2025 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS ... |
| CVE-2025-57118 | CRITICAL | 9.8 | 0.5% | Sep 15, 2025 | An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php |
| CVE-2025-10482 | CRITICAL | 9.8 | 0.5% | Sep 15, 2025 | A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio... |
| CVE-2025-10480 | CRITICAL | 9.8 | 0.3% | Sep 15, 2025 | A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown func... |
| CVE-2025-10479 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is... |
| CVE-2025-10477 | CRITICAL | 9.8 | 0.3% | Sep 15, 2025 | A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec... |
| CVE-2025-10473 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the f... |
| CVE-2025-58748 | CRITICAL | 9.8 | 0.8% | Sep 15, 2025 | Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data sou... |
| CVE-2025-57174 | CRITICAL | 9.8 | 1.2% | Sep 15, 2025 | An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and p... |
| CVE-2025-58046 | CRITICAL | 9.8 | 1.3% | Sep 15, 2025 | Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala... |
| CVE-2025-58045 | CRITICAL | 9.8 | 0.6% | Sep 15, 2025 | Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12, the patch intr... |
| CVE-2025-52053 | CRITICAL | 9.8 | 4.4% | Sep 15, 2025 | TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 functio... |
| CVE-2025-10459 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of ... |
| CVE-2025-59377 | CRITICAL | 9.8 | 1.2% | Sep 15, 2025 | feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl beca... |
| CVE-2025-46408 | CRITICAL | 9.8 | 0.6% | Sep 15, 2025 | An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_Htt... |
| CVE-2025-10448 | CRITICAL | 9.8 | 0.5% | Sep 15, 2025 | A flaw has been found in Campcodes Online Job Finder System 1.0. This affects an unknown function of the file /index.php... |
| CVE-2025-10447 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of t... |
| CVE-2025-10446 | CRITICAL | 9.8 | 0.4% | Sep 15, 2025 | A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. The affected element is... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now