2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71424 | LOW | 3.5 | 0.2% | Sep 27, 2026 | Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and includi... |
| CVE-2025-1218 | LOW | 3.4 | 0.2% | Sep 25, 2026 | The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough b... |
| CVE-2025-15698 | LOW | 3.5 | 0.1% | Sep 19, 2026 | The Business Name Generator WordPress plugin through 1.3 does not sanitise and escape some of its settings, which could ... |
| CVE-2025-13166 | LOW | 3.7 | 0.2% | Sep 15, 2026 | The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered us... |
| CVE-2025-26790 | LOW | 3.7 | 0.3% | Sep 14, 2026 | Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memo... |
| CVE-2025-64031 | LOW | 2.5 | 0.1% | Sep 14, 2026 | libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field... |
| CVE-2025-70820 | LOW | 3.5 | 0.2% | Sep 13, 2026 | Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder. |
| CVE-2025-64059 | LOW | 1.8 | 0.2% | Sep 13, 2026 | Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is ... |
| CVE-2025-45480 | LOW | 3 | 0.2% | Sep 13, 2026 | Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary. |
| CVE-2025-15695 | LOW | 3.5 | 0.2% | Sep 11, 2026 | The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the ... |
| CVE-2025-52657 | LOW | 3.5 | 0.2% | Sep 7, 2026 | HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the... |
| CVE-2025-52652 | LOW | 3.5 | 0.1% | Sep 7, 2026 | HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content,... |
| CVE-2025-52651 | LOW | 3.5 | 0.1% | Sep 7, 2026 | HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause u... |
| CVE-2025-15614 | LOW | 3.3 | 0.1% | Sep 5, 2026 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z arc... |
| CVE-2025-15694 | LOW | 3.5 | 0.2% | Sep 5, 2026 | The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before output... |
| CVE-2025-15693 | LOW | 2.7 | 0.3% | Sep 5, 2026 | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its admini... |
| CVE-2025-15692 | LOW | 3.5 | 0.2% | Sep 2, 2026 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting ... |
| CVE-2025-62343 | LOW | 3.1 | 0.2% | Aug 27, 2026 | HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sess... |
| CVE-2025-62341 | LOW | 3.7 | 0.1% | Aug 26, 2026 | HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allo... |
| CVE-2025-62318 | LOW | 3.7 | — | Aug 13, 2026 | HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages... |
| CVE-2025-62315 | LOW | 3.4 | — | Aug 13, 2026 | HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validatio... |
| CVE-2025-9486 | LOW | 3.3 | — | Aug 12, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2... |
| CVE-2025-61970 | LOW | 1 | — | Aug 11, 2026 | Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to ... |
| CVE-2025-48505 | LOW | 1 | 0.1% | Aug 11, 2026 | Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to ... |
| CVE-2025-15680 | LOW | 2.4 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now