2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10251 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/adm... |
| CVE-2025-40692 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40691 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40690 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40689 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40687 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-58321 | CRITICAL | 10 | 1.2% | Sep 11, 2025 | Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability. |
| CVE-2025-8570 | CRITICAL | 9.8 | 0.6% | Sep 11, 2025 | The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret managemen... |
| CVE-2025-10218 | CRITICAL | 9.8 | 0.3% | Sep 10, 2025 | A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/d... |
| CVE-2025-54123 | CRITICAL | 9.8 | 10.5% | Sep 10, 2025 | Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly i... |
| CVE-2025-59041 | CRITICAL | 9.8 | 0.5% | Sep 10, 2025 | Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.ema... |
| CVE-2025-58764 | CRITICAL | 9.8 | 0.5% | Sep 10, 2025 | Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to ... |
| CVE-2025-10226 | CRITICAL | 9.8 | 0.6% | Sep 10, 2025 | Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.... |
| CVE-2025-10220 | CRITICAL | 9.8 | 0.7% | Sep 10, 2025 | Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.... |
| CVE-2025-9943 | CRITICAL | 9.1 | 0.4% | Sep 10, 2025 | An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of t... |
| CVE-2025-59046 | CRITICAL | 9.8 | 1.2% | Sep 9, 2025 | The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branc... |
| CVE-2025-59039 | CRITICAL | 9.3 | 0.3% | Sep 9, 2025 | Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest we... |
| CVE-2025-58750 | CRITICAL | 9.1 | 0.3% | Sep 9, 2025 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ... |
| CVE-2025-58448 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ... |
| CVE-2025-58447 | CRITICAL | 9.8 | 0.8% | Sep 9, 2025 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ... |
| CVE-2025-58768 | CRITICAL | 9.6 | 0.6% | Sep 9, 2025 | DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering compo... |
| CVE-2025-58462 | CRITICAL | 9.8 | 0.6% | Sep 9, 2025 | OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A r... |
| CVE-2025-57633 | CRITICAL | 9.8 | 1.5% | Sep 9, 2025 | A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute... |
| CVE-2025-43491 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the fi... |
| CVE-2025-23344 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now