2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29365 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL. |
| CVE-2025-9254 | CRITICAL | 9.8 | 0.6% | Aug 22, 2025 | WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log ... |
| CVE-2025-53795 | CRITICAL | 9.8 | 0.6% | Aug 21, 2025 | Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-53763 | CRITICAL | 9.8 | 0.6% | Aug 21, 2025 | Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-3128 | CRITICAL | 9.8 | 0.7% | Aug 21, 2025 | A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamp... |
| CVE-2025-52352 | CRITICAL | 9.8 | 0.5% | Aug 21, 2025 | Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed d... |
| CVE-2025-9311 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A vulnerability was identified in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown f... |
| CVE-2025-57754 | CRITICAL | 9.8 | 0.3% | Aug 21, 2025 | eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is ex... |
| CVE-2025-9307 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/... |
| CVE-2025-52395 | CRITICAL | 9.8 | 0.5% | Aug 21, 2025 | An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password ... |
| CVE-2025-9305 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is ... |
| CVE-2025-9304 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A weakness has been identified in SourceCodester Online Bank Management System 1.0. Impacted is an unknown function of t... |
| CVE-2025-9303 | CRITICAL | 9.8 | 0.8% | Aug 21, 2025 | A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParental... |
| CVE-2025-53251 | CRITICAL | 9.9 | 0.3% | Aug 21, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP pin-wp allows Upload a Web Shell to a ... |
| CVE-2025-9302 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the ... |
| CVE-2025-9299 | CRITICAL | 9.8 | 4.3% | Aug 21, 2025 | A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPasseng... |
| CVE-2025-9298 | CRITICAL | 9.8 | 1.0% | Aug 21, 2025 | A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Exec... |
| CVE-2025-9296 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admi... |
| CVE-2025-8895 | CRITICAL | 9.8 | 0.5% | Aug 21, 2025 | The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied inp... |
| CVE-2025-7390 | CRITICAL | 9.1 | 0.2% | Aug 21, 2025 | A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is conf... |
| CVE-2025-43300 | CRITICAL | 10 | 20.0% | Aug 21, 2025 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1... |
| CVE-2025-27217 | CRITICAL | 9.1 | 0.4% | Aug 21, 2025 | A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to mak... |
| CVE-2025-27214 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious a... |
| CVE-2025-24285 | CRITICAL | 9.8 | 1.2% | Aug 21, 2025 | Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a m... |
| CVE-2025-9288 | CRITICAL | 9.1 | 0.7% | Aug 20, 2025 | Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now