2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9113 | CRITICAL | 9.8 | 0.6% | Sep 8, 2025 | The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the... |
| CVE-2025-10103 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the... |
| CVE-2025-10102 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function o... |
| CVE-2025-57285 | CRITICAL | 9.8 | 2.2% | Sep 8, 2025 | codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync com... |
| CVE-2025-56267 | CRITICAL | 9.8 | 0.7% | Sep 8, 2025 | A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitr... |
| CVE-2025-56266 | CRITICAL | 9.8 | 2.7% | Sep 8, 2025 | A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplyin... |
| CVE-2025-10100 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of t... |
| CVE-2025-10097 | CRITICAL | 9.8 | 0.7% | Sep 8, 2025 | A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app... |
| CVE-2025-57141 | CRITICAL | 9.8 | 0.7% | Sep 8, 2025 | rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc. |
| CVE-2025-52161 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vu... |
| CVE-2025-22956 | CRITICAL | 9.8 | 0.3% | Sep 8, 2025 | OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead ... |
| CVE-2025-10092 | CRITICAL | 9.8 | 0.5% | Sep 8, 2025 | A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectman... |
| CVE-2025-5993 | CRITICAL | 9.2 | 0.6% | Sep 8, 2025 | ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is ab... |
| CVE-2025-10091 | CRITICAL | 9.8 | 0.5% | Sep 8, 2025 | A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.proje... |
| CVE-2025-10090 | CRITICAL | 9.8 | 1.7% | Sep 8, 2025 | A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.dep... |
| CVE-2025-10082 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file ... |
| CVE-2025-10079 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the fil... |
| CVE-2025-10078 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /a... |
| CVE-2025-10077 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function... |
| CVE-2025-10076 | CRITICAL | 9.8 | 0.4% | Sep 8, 2025 | A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file... |
| CVE-2025-10068 | CRITICAL | 9.8 | 0.4% | Sep 7, 2025 | A flaw has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin/a... |
| CVE-2025-10062 | CRITICAL | 9.8 | 0.4% | Sep 6, 2025 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part o... |
| CVE-2025-58443 | CRITICAL | 9.1 | 17.6% | Sep 6, 2025 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below conta... |
| CVE-2025-58438 | CRITICAL | 9.4 | 1.4% | Sep 6, 2025 | internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory ... |
| CVE-2025-10034 | CRITICAL | 9.8 | 0.9% | Sep 6, 2025 | A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_resp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now