2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10134 | CRITICAL | 9.1 | 0.5% | Sep 9, 2025 | The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffi... |
| CVE-2025-10123 | CRITICAL | 9.8 | 4.0% | Sep 9, 2025 | A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_41502... |
| CVE-2025-42958 | CRITICAL | 9.1 | 0.7% | Sep 9, 2025 | Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high priv... |
| CVE-2025-42944 | CRITICAL | 10 | 2.9% | Sep 9, 2025 | Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through th... |
| CVE-2025-42922 | CRITICAL | 9.9 | 0.7% | Sep 9, 2025 | SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available servic... |
| CVE-2025-10118 | CRITICAL | 9.8 | 0.5% | Sep 9, 2025 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The... |
| CVE-2025-10114 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file ... |
| CVE-2025-10113 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an un... |
| CVE-2025-10112 | CRITICAL | 9.8 | 0.4% | Sep 9, 2025 | A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unk... |
| CVE-2025-58746 | CRITICAL | 9 | 0.3% | Sep 8, 2025 | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashbo... |
| CVE-2025-10111 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a... |
| CVE-2025-10109 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processin... |
| CVE-2025-58450 | CRITICAL | 9.3 | 0.3% | Sep 8, 2025 | pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible... |
| CVE-2025-10108 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the... |
| CVE-2025-54994 | CRITICAL | 9.3 | 1.4% | Sep 8, 2025 | @akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13... |
| CVE-2025-10104 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown func... |
| CVE-2025-9114 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0.... |
| CVE-2025-9113 | CRITICAL | 9.8 | 0.6% | Sep 8, 2025 | The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the... |
| CVE-2025-10103 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the... |
| CVE-2025-10102 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function o... |
| CVE-2025-57285 | CRITICAL | 9.8 | 2.2% | Sep 8, 2025 | codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync com... |
| CVE-2025-56267 | CRITICAL | 9.8 | 0.7% | Sep 8, 2025 | A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitr... |
| CVE-2025-56266 | CRITICAL | 9.8 | 2.7% | Sep 8, 2025 | A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplyin... |
| CVE-2025-10100 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of t... |
| CVE-2025-10097 | CRITICAL | 9.8 | 0.7% | Sep 8, 2025 | A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now