2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45968 | CRITICAL | 9.8 | 0.6% | Aug 25, 2025 | An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. Th... |
| CVE-2025-29515 | CRITICAL | 9.8 | 0.6% | Aug 25, 2025 | Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allo... |
| CVE-2025-29514 | CRITICAL | 9.8 | 0.6% | Aug 25, 2025 | Incorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows ... |
| CVE-2025-7426 | CRITICAL | 9.3 | 0.3% | Aug 25, 2025 | Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service... |
| CVE-2025-9118 | CRITICAL | 10 | 0.6% | Aug 25, 2025 | A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker... |
| CVE-2025-9406 | CRITICAL | 9.8 | 0.3% | Aug 25, 2025 | A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsAr... |
| CVE-2025-9397 | CRITICAL | 9.8 | 0.5% | Aug 24, 2025 | A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits... |
| CVE-2025-9391 | CRITICAL | 9.8 | 0.4% | Aug 24, 2025 | A weakness has been identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this issue is the function getFieldValue of ... |
| CVE-2025-9387 | CRITICAL | 9.8 | 9.3% | Aug 24, 2025 | A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function... |
| CVE-2025-36157 | CRITICAL | 9.1 | 0.5% | Aug 24, 2025 | IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenti... |
| CVE-2025-5821 | CRITICAL | 9.8 | 0.7% | Aug 23, 2025 | The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.... |
| CVE-2025-5352 | CRITICAL | 9.6 | 0.5% | Aug 23, 2025 | A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of lunary-ai/lunary version... |
| CVE-2025-7642 | CRITICAL | 9.8 | 0.5% | Aug 23, 2025 | The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due... |
| CVE-2025-43766 | CRITICAL | 9.8 | 0.4% | Aug 23, 2025 | The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2... |
| CVE-2025-4609 | CRITICAL | 9.6 | 0.4% | Aug 22, 2025 | Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allow... |
| CVE-2025-26496 | CRITICAL | 9.3 | 0.2% | Aug 22, 2025 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Deskto... |
| CVE-2025-57801 | CRITICAL | 9.1 | 0.2% | Aug 22, 2025 | gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa... |
| CVE-2025-51092 | CRITICAL | 9.8 | 0.4% | Aug 22, 2025 | The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in ... |
| CVE-2025-55613 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter. |
| CVE-2025-57105 | CRITICAL | 9.8 | 3.7% | Aug 22, 2025 | The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the ... |
| CVE-2025-55637 | CRITICAL | 9.8 | 1.7% | Aug 22, 2025 | Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a ... |
| CVE-2025-55619 | CRITICAL | 9.8 | 0.4% | Aug 22, 2025 | Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker c... |
| CVE-2025-55398 | CRITICAL | 9.8 | 0.3% | Aug 22, 2025 | An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed En... |
| CVE-2025-52095 | CRITICAL | 9.8 | 0.3% | Aug 22, 2025 | An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines... |
| CVE-2025-29366 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | In mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and write_rdram_regs functions, w... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now