2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41770 | HIGH | 7.5 | — | Aug 12, 2026 | An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an rem... |
| CVE-2025-54512 | HIGH | 7 | — | Aug 11, 2026 | A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to e... |
| CVE-2025-0046 | HIGH | 7 | — | Aug 11, 2026 | Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrar... |
| CVE-2025-8087 | HIGH | 7 | — | Aug 11, 2026 | A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges ... |
| CVE-2025-31936 | HIGH | 7 | — | Aug 11, 2026 | Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) ... |
| CVE-2025-30241 | HIGH | 8.6 | — | Aug 10, 2026 | Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input pro... |
| CVE-2025-30239 | HIGH | 8.5 | 0.1% | Aug 10, 2026 | In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive co... |
| CVE-2025-30238 | HIGH | 8.6 | 0.1% | Aug 10, 2026 | In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e... |
| CVE-2025-30237 | HIGH | 8.7 | 0.2% | Aug 10, 2026 | The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not c... |
| CVE-2025-15683 | HIGH | 8.8 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An ... |
| CVE-2025-15682 | HIGH | 8.7 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauth... |
| CVE-2025-71412 | HIGH | 7.1 | 0.2% | Aug 7, 2026 | Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion... |
| CVE-2025-71409 | HIGH | 7.1 | 0.2% | Aug 7, 2026 | Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages ... |
| CVE-2025-63235 | HIGH | 7.5 | — | Aug 7, 2026 | In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON... |
| CVE-2025-49506 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or p... |
| CVE-2025-15028 | HIGH | 7.2 | — | Aug 6, 2026 | The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is ... |
| CVE-2025-63822 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate... |
| CVE-2025-70962 | HIGH | 7.5 | — | Aug 5, 2026 | Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials ... |
| CVE-2025-15629 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati... |
| CVE-2025-15628 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr... |
| CVE-2025-15627 | HIGH | 7.5 | 0.2% | Aug 3, 2026 | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to... |
| CVE-2025-15672 | HIGH | 8.1 | 0.2% | Aug 3, 2026 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa... |
| CVE-2025-71400 | HIGH | 7.1 | 0.2% | Aug 2, 2026 | better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet... |
| CVE-2025-71399 | HIGH | 8.8 | 0.3% | Aug 2, 2026 | Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize... |
| CVE-2025-71403 | HIGH | 7.1 | 0.2% | Aug 1, 2026 | better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now