2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41771 | MEDIUM | 5.3 | — | Aug 12, 2026 | An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl... |
| CVE-2025-15687 | MEDIUM | 4.3 | — | Aug 12, 2026 | A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF ... |
| CVE-2025-15686 | MEDIUM | 4.3 | — | Aug 12, 2026 | A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the com... |
| CVE-2025-15685 | MEDIUM | 6.3 | — | Aug 12, 2026 | A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the componen... |
| CVE-2025-15684 | MEDIUM | 5.3 | — | Aug 12, 2026 | A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/com... |
| CVE-2025-48506 | MEDIUM | 4.6 | — | Aug 11, 2026 | Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into t... |
| CVE-2025-35987 | MEDIUM | 4.3 | — | Aug 11, 2026 | Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives... |
| CVE-2025-35973 | MEDIUM | 4.5 | — | Aug 11, 2026 | Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow a... |
| CVE-2025-31938 | MEDIUM | 4.3 | — | Aug 11, 2026 | Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(... |
| CVE-2025-31356 | MEDIUM | 5.6 | — | Aug 11, 2026 | Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: H... |
| CVE-2025-0041 | MEDIUM | 4.6 | — | Aug 11, 2026 | Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a... |
| CVE-2025-30240 | MEDIUM | 5.1 | — | Aug 10, 2026 | The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By ... |
| CVE-2025-32736 | MEDIUM | 4.9 | 0.2% | Aug 10, 2026 | Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may all... |
| CVE-2025-71413 | MEDIUM | 6 | 0.2% | Aug 7, 2026 | Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w... |
| CVE-2025-71411 | MEDIUM | 6 | 0.2% | Aug 7, 2026 | Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic c... |
| CVE-2025-71410 | MEDIUM | 6 | 0.2% | Aug 7, 2026 | Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and... |
| CVE-2025-6508 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b... |
| CVE-2025-12317 | MEDIUM | 5 | 0.2% | Aug 6, 2026 | When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue... |
| CVE-2025-9266 | MEDIUM | 4.3 | — | Aug 6, 2026 | The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2025-13909 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT... |
| CVE-2025-13394 | MEDIUM | 5.4 | 0.1% | Aug 6, 2026 | The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque... |
| CVE-2025-11850 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us... |
| CVE-2025-15678 | MEDIUM | 6.1 | 0.2% | Aug 6, 2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use... |
| CVE-2025-15631 | MEDIUM | 5.9 | 0.1% | Aug 3, 2026 | A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al... |
| CVE-2025-15630 | MEDIUM | 5.9 | 0.2% | Aug 3, 2026 | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now