2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47569 | CRITICAL | 9.3 | 0.6% | Sep 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommer... |
| CVE-2025-32486 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.T... |
| CVE-2025-10183 | CRITICAL | 9.1 | 0.4% | Sep 9, 2025 | A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthent... |
| CVE-2025-9994 | CRITICAL | 9.8 | 0.5% | Sep 9, 2025 | The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing ... |
| CVE-2025-54236 | CRITICAL | 9.1 | 96.7% | Sep 9, 2025 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an... |
| CVE-2025-40804 | CRITICAL | 9.3 | 0.4% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected applica... |
| CVE-2025-40795 | CRITICAL | 9.8 | 0.7% | Sep 9, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC... |
| CVE-2025-40594 | CRITICAL | 9.8 | 0.2% | Sep 9, 2025 | A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < ... |
| CVE-2025-10134 | CRITICAL | 9.1 | 0.5% | Sep 9, 2025 | The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffi... |
| CVE-2025-10123 | CRITICAL | 9.8 | 4.0% | Sep 9, 2025 | A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_41502... |
| CVE-2025-42958 | CRITICAL | 9.1 | 0.7% | Sep 9, 2025 | Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high priv... |
| CVE-2025-42944 | CRITICAL | 10 | 2.9% | Sep 9, 2025 | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through th... |
| CVE-2025-42922 | CRITICAL | 9.9 | 0.7% | Sep 9, 2025 | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available servic... |
| CVE-2025-10118 | CRITICAL | 9.8 | 0.5% | Sep 9, 2025 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The... |
| CVE-2025-10114 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file ... |
| CVE-2025-10113 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an un... |
| CVE-2025-10112 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unk... |
| CVE-2025-58746 | CRITICAL | 9 | 0.3% | Sep 8, 2025 | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashbo... |
| CVE-2025-10111 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a... |
| CVE-2025-10109 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processin... |
| CVE-2025-58450 | CRITICAL | 9.3 | 0.3% | Sep 8, 2025 | pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible... |
| CVE-2025-10108 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the... |
| CVE-2025-54994 | CRITICAL | 9.3 | 1.4% | Sep 8, 2025 | @akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13... |
| CVE-2025-10104 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown func... |
| CVE-2025-9114 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now