2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10033 | CRITICAL | 9.8 | 0.4% | Sep 6, 2025 | A vulnerability has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file... |
| CVE-2025-10031 | CRITICAL | 9.8 | 0.4% | Sep 6, 2025 | A security vulnerability has been detected in Campcodes Grocery Sales and Inventory System 1.0. Impacted is an unknown f... |
| CVE-2025-10030 | CRITICAL | 9.8 | 0.4% | Sep 6, 2025 | A weakness has been identified in Campcodes Grocery Sales and Inventory System 1.0. This issue affects some unknown proc... |
| CVE-2025-8359 | CRITICAL | 9.8 | 0.5% | Sep 6, 2025 | The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. Thi... |
| CVE-2025-58439 | CRITICAL | 9.1 | 0.3% | Sep 6, 2025 | ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, l... |
| CVE-2025-58372 | CRITICAL | 9.8 | 0.5% | Sep 5, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vul... |
| CVE-2025-58371 | CRITICAL | 9.8 | 0.8% | Sep 5, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github w... |
| CVE-2025-58367 | CRITICAL | 10 | 1.1% | Sep 5, 2025 | DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnera... |
| CVE-2025-58366 | CRITICAL | 9.4 | 0.3% | Sep 5, 2025 | Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials ... |
| CVE-2025-57807 | CRITICAL | 9.8 | 0.3% | Sep 5, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lowe... |
| CVE-2025-10025 | CRITICAL | 9.8 | 0.4% | Sep 5, 2025 | A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file... |
| CVE-2025-35452 | CRITICAL | 9.8 | 0.8% | Sep 5, 2025 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative ... |
| CVE-2025-35451 | CRITICAL | 9.8 | 0.7% | Sep 5, 2025 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The... |
| CVE-2025-58628 | CRITICAL | 9.3 | 0.3% | Sep 5, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Mirac... |
| CVE-2025-58206 | CRITICAL | 9.8 | 0.4% | Sep 5, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49401 | CRITICAL | 9.8 | 0.4% | Sep 5, 2025 | Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue af... |
| CVE-2025-58819 | CRITICAL | 9.1 | 0.3% | Sep 5, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allow... |
| CVE-2025-55037 | CRITICAL | 9.8 | 2.7% | Sep 5, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI ver... |
| CVE-2025-55244 | CRITICAL | 9 | 0.6% | Sep 4, 2025 | Azure Bot Service Elevation of Privilege Vulnerability |
| CVE-2025-55241 | CRITICAL | 10 | 1.5% | Sep 4, 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-55190 | CRITICAL | 9.9 | 4.5% | Sep 4, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 thro... |
| CVE-2025-54914 | CRITICAL | 9.8 | 2.2% | Sep 4, 2025 | Azure Networking Elevation of Privilege Vulnerability |
| CVE-2025-58361 | CRITICAL | 9.3 | 0.3% | Sep 4, 2025 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version... |
| CVE-2025-8311 | CRITICAL | 9.4 | 1.6% | Sep 4, 2025 | dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpo... |
| CVE-2025-7385 | CRITICAL | 9.3 | 0.4% | Sep 4, 2025 | Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now