2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41034 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-41033 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-41032 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c... |
| CVE-2025-9935 | CRITICAL | 9.8 | 3.0% | Sep 4, 2025 | A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_415... |
| CVE-2025-9934 | CRITICAL | 9.8 | 3.7% | Sep 4, 2025 | A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /c... |
| CVE-2025-9933 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknow... |
| CVE-2025-9932 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown f... |
| CVE-2025-9930 | CRITICAL | 9.8 | 0.4% | Sep 4, 2025 | A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown... |
| CVE-2025-58357 | CRITICAL | 9.6 | 0.6% | Sep 4, 2025 | 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 con... |
| CVE-2025-36904 | CRITICAL | 9.8 | 0.2% | Sep 4, 2025 | WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384. |
| CVE-2025-36897 | CRITICAL | 9.8 | 0.3% | Sep 4, 2025 | In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This coul... |
| CVE-2025-36896 | CRITICAL | 9.8 | 0.2% | Sep 4, 2025 | WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106. |
| CVE-2025-36890 | CRITICAL | 9.8 | 0.2% | Sep 4, 2025 | Elevation of Privilege |
| CVE-2025-9928 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown fu... |
| CVE-2025-9927 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown functio... |
| CVE-2025-55747 | CRITICAL | 9.1 | 1.6% | Sep 3, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.... |
| CVE-2025-9926 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the fil... |
| CVE-2025-9925 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability was found in projectworlds Travel Management System 1.0. This issue affects some unknown processing of t... |
| CVE-2025-53690 | CRITICAL | 9 | 26.3% | Sep 3, 2025 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a... |
| CVE-2025-9924 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of... |
| CVE-2025-56752 | CRITICAL | 9.4 | 0.5% | Sep 3, 2025 | A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass auth... |
| CVE-2025-9919 | CRITICAL | 9.8 | 0.4% | Sep 3, 2025 | A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of... |
| CVE-2025-57148 | CRITICAL | 9.1 | 0.4% | Sep 3, 2025 | phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the la... |
| CVE-2025-57052 | CRITICAL | 9.8 | 0.7% | Sep 3, 2025 | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c... |
| CVE-2025-53693 | CRITICAL | 9.8 | 13.8% | Sep 3, 2025 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Ex... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now