2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23343 | CRITICAL | 9.8 | 0.7% | Sep 9, 2025 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A succ... |
| CVE-2025-23342 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A succ... |
| CVE-2025-10159 | CRITICAL | 9.8 | 0.8% | Sep 9, 2025 | An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wi... |
| CVE-2025-44594 | CRITICAL | 9.1 | 0.3% | Sep 9, 2025 | halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/a... |
| CVE-2025-55730 | CRITICAL | 10 | 0.7% | Sep 9, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ... |
| CVE-2025-55729 | CRITICAL | 10 | 0.7% | Sep 9, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ... |
| CVE-2025-55728 | CRITICAL | 9.8 | 0.7% | Sep 9, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ... |
| CVE-2025-55727 | CRITICAL | 9.8 | 1.0% | Sep 9, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ... |
| CVE-2025-55051 | CRITICAL | 10 | 0.3% | Sep 9, 2025 | CWE-1392: Use of Default Credentials |
| CVE-2025-55050 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | CWE-1242: Inclusion of Undocumented Features |
| CVE-2025-55049 | CRITICAL | 9.1 | 0.3% | Sep 9, 2025 | Use of Default Cryptographic Key (CWE-1394) |
| CVE-2025-55048 | CRITICAL | 9.8 | 0.5% | Sep 9, 2025 | Multiple CWE-78 |
| CVE-2025-57085 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function.... |
| CVE-2025-58997 | CRITICAL | 9.6 | 0.2% | Sep 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/... |
| CVE-2025-55234 | CRITICAL | 9.8 | 18.8% | Sep 9, 2025 | SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited ... |
| CVE-2025-55232 | CRITICAL | 9.8 | 1.9% | Sep 9, 2025 | Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to ex... |
| CVE-2025-54261 | CRITICAL | 10 | 19.9% | Sep 9, 2025 | ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restr... |
| CVE-2025-47569 | CRITICAL | 9.3 | 0.6% | Sep 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommer... |
| CVE-2025-32486 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.T... |
| CVE-2025-10183 | CRITICAL | 9.1 | 0.4% | Sep 9, 2025 | A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthent... |
| CVE-2025-9994 | CRITICAL | 9.8 | 0.5% | Sep 9, 2025 | The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing ... |
| CVE-2025-54236 | CRITICAL | 9.1 | 96.7% | Sep 9, 2025 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an... |
| CVE-2025-40804 | CRITICAL | 9.3 | 0.4% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected applica... |
| CVE-2025-40795 | CRITICAL | 9.8 | 0.7% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
| CVE-2025-40594 | CRITICAL | 9.8 | 0.2% | Sep 9, 2025 | A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now