2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21042 | CRITICAL | 9.8 | 11.6% | Sep 12, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra... |
| CVE-2025-55319 | CRITICAL | 9.8 | 0.8% | Sep 12, 2025 | Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network... |
| CVE-2025-36222 | CRITICAL | 9.8 | 0.4% | Sep 11, 2025 | IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.... |
| CVE-2025-10127 | CRITICAL | 9.8 | 0.6% | Sep 11, 2025 | Daikin Europe N.V Security Gateway is vulnerable to an authorization bypass through a user-controlled key vulnerabilit... |
| CVE-2025-59053 | CRITICAL | 9.6 | 0.5% | Sep 11, 2025 | AIRI is a self-hosted, artificial intelligence based Grok Companion. In v0.7.2-beta.2 in the `packages/stage-ui/src/comp... |
| CVE-2025-58143 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-58142 | CRITICAL | 9.8 | 0.4% | Sep 11, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-27466 | CRITICAL | 9.8 | 0.4% | Sep 11, 2025 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-10251 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/adm... |
| CVE-2025-40692 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40691 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40690 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40689 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40687 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-58321 | CRITICAL | 10 | 1.2% | Sep 11, 2025 | Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability. |
| CVE-2025-8570 | CRITICAL | 9.8 | 0.6% | Sep 11, 2025 | The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret managemen... |
| CVE-2025-10218 | CRITICAL | 9.8 | 0.3% | Sep 10, 2025 | A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/d... |
| CVE-2025-54123 | CRITICAL | 9.8 | 10.5% | Sep 10, 2025 | Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly i... |
| CVE-2025-59041 | CRITICAL | 9.8 | 0.5% | Sep 10, 2025 | Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.ema... |
| CVE-2025-58764 | CRITICAL | 9.8 | 0.5% | Sep 10, 2025 | Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to ... |
| CVE-2025-10226 | CRITICAL | 9.8 | 0.6% | Sep 10, 2025 | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.... |
| CVE-2025-10220 | CRITICAL | 9.8 | 0.7% | Sep 10, 2025 | Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.... |
| CVE-2025-9943 | CRITICAL | 9.1 | 0.4% | Sep 10, 2025 | An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of t... |
| CVE-2025-59046 | CRITICAL | 9.8 | 1.2% | Sep 9, 2025 | The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branc... |
| CVE-2025-59039 | CRITICAL | 9.3 | 0.3% | Sep 9, 2025 | Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest we... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now