2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8178HIGH8.8A vulnerability classified as critical has been found in Tenda AC10 16.03.10.13. Affected is an unknown function of the ...
CVE-2025-6895CRITICAL9.8The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization wi...
CVE-2025-8177HIGH7.8A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow ...
CVE-2025-8176HIGH7.8A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the funct...
CVE-2025-8103MEDIUM4.3The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-54416CRITICAL9.1tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with supp...
CVE-2025-54415CRITICAL9.1dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0...
CVE-2025-54414MEDIUM5.1Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to ...
CVE-2025-54413HIGH8.7skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below co...
CVE-2025-54412HIGH8.7skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below co...
CVE-2025-54385CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions bet...
CVE-2025-54380MEDIUM6.5Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to vers...
CVE-2025-54378HIGH8.3HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcm...
CVE-2025-54366HIGH8.8FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1...
CVE-2025-50185HIGH7DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to in...
CVE-2025-50184HIGH7.1DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directo...
CVE-2025-8175HIGH7.5A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown p...
CVE-2025-8174MEDIUM6.3A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some ...
CVE-2025-8173CRITICAL9.8A vulnerability has been found in 1000 Projects ABC Courier Management System 1.0 and classified as critical. Affected b...
CVE-2025-8172HIGH8.8A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System 1.0. Affected is...
CVE-2025-8171MEDIUM6.3A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This ...
CVE-2025-8101HIGH8.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Linkify (link...
CVE-2025-8170HIGH8.8A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. This vulnerability affects the fu...
CVE-2025-8169CRITICAL9.8A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function formSetWanPPTPca...
CVE-2025-8197Rejected reason: Maintainers have included reasons at https://gitlab.gnome.org/GNOME/libsoup/-/issues/465

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now