2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9287 | CRITICAL | 9.1 | 0.5% | Aug 20, 2025 | Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: th... |
| CVE-2025-8611 | CRITICAL | 9.8 | 0.8% | Aug 20, 2025 | AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2025-8610 | CRITICAL | 9.8 | 0.8% | Aug 20, 2025 | AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2025-55444 | CRITICAL | 9.8 | 0.8% | Aug 20, 2025 | A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts... |
| CVE-2025-50904 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can... |
| CVE-2025-50901 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, whi... |
| CVE-2025-9074 | CRITICAL | 9.3 | 1.6% | Aug 20, 2025 | A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine ... |
| CVE-2025-32010 | CRITICAL | 9.8 | 0.6% | Aug 20, 2025 | A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A spe... |
| CVE-2025-31355 | CRITICAL | 9.8 | 0.3% | Aug 20, 2025 | A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.11... |
| CVE-2025-27129 | CRITICAL | 9.8 | 2.0% | Aug 20, 2025 | An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. ... |
| CVE-2025-24322 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.... |
| CVE-2025-54726 | CRITICAL | 9.3 | 1.4% | Aug 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS A... |
| CVE-2025-54713 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCom... |
| CVE-2025-54049 | CRITICAL | 9.9 | 0.4% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalati... |
| CVE-2025-54048 | CRITICAL | 9.3 | 0.4% | Aug 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom ... |
| CVE-2025-54014 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Obj... |
| CVE-2025-53580 | CRITICAL | 9.8 | 0.3% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro... |
| CVE-2025-53577 | CRITICAL | 10 | 0.4% | Aug 20, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS global-dns allows Remote Cod... |
| CVE-2025-53299 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer ... |
| CVE-2025-53213 | CRITICAL | 9.9 | 0.3% | Aug 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Cond... |
| CVE-2025-49890 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in ThemeREX Organic Beauty organic-beauty allows Object Injection.This i... |
| CVE-2025-49434 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in axiomthemes Cars4Rent cars4rent allows Object Injection.This issue af... |
| CVE-2025-49422 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.T... |
| CVE-2025-49410 | CRITICAL | 10 | 0.5% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testi... |
| CVE-2025-49409 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SensorPre... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now