2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58750 | CRITICAL | 9.1 | 0.3% | Sep 9, 2025 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ... |
| CVE-2025-58448 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ... |
| CVE-2025-58447 | CRITICAL | 9.8 | 0.8% | Sep 9, 2025 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ... |
| CVE-2025-58768 | CRITICAL | 9.6 | 0.6% | Sep 9, 2025 | DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering compo... |
| CVE-2025-58462 | CRITICAL | 9.8 | 0.6% | Sep 9, 2025 | OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A r... |
| CVE-2025-57633 | CRITICAL | 9.8 | 1.5% | Sep 9, 2025 | A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute... |
| CVE-2025-43491 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the fi... |
| CVE-2025-23344 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privi... |
| CVE-2025-23343 | CRITICAL | 9.8 | 0.7% | Sep 9, 2025 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A succ... |
| CVE-2025-23342 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A succ... |
| CVE-2025-10159 | CRITICAL | 9.8 | 0.8% | Sep 9, 2025 | An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wi... |
| CVE-2025-44594 | CRITICAL | 9.1 | 0.3% | Sep 9, 2025 | halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/a... |
| CVE-2025-55730 | CRITICAL | 10 | 0.7% | Sep 9, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ... |
| CVE-2025-55729 | CRITICAL | 10 | 0.7% | Sep 9, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ... |
| CVE-2025-55728 | CRITICAL | 9.8 | 0.7% | Sep 9, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ... |
| CVE-2025-55727 | CRITICAL | 9.8 | 1.0% | Sep 9, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ... |
| CVE-2025-55051 | CRITICAL | 10 | 0.3% | Sep 9, 2025 | CWE-1392: Use of Default Credentials |
| CVE-2025-55050 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | CWE-1242: Inclusion of Undocumented Features |
| CVE-2025-55049 | CRITICAL | 9.1 | 0.3% | Sep 9, 2025 | Use of Default Cryptographic Key (CWE-1394) |
| CVE-2025-55048 | CRITICAL | 9.8 | 0.5% | Sep 9, 2025 | Multiple CWE-78 |
| CVE-2025-57085 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function.... |
| CVE-2025-58997 | CRITICAL | 9.6 | 0.2% | Sep 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/... |
| CVE-2025-55234 | CRITICAL | 9.8 | 18.8% | Sep 9, 2025 | SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited ... |
| CVE-2025-55232 | CRITICAL | 9.8 | 1.9% | Sep 9, 2025 | Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to ex... |
| CVE-2025-54261 | CRITICAL | 10 | 19.9% | Sep 9, 2025 | ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now