2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54145 | CRITICAL | 9.1 | 0.4% | Aug 19, 2025 | The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that lev... |
| CVE-2025-54143 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictio... |
| CVE-2025-9156 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of t... |
| CVE-2025-9155 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown func... |
| CVE-2025-51543 | CRITICAL | 9.8 | 0.3% | Aug 19, 2025 | An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /admini... |
| CVE-2025-9154 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown proc... |
| CVE-2025-55733 | CRITICAL | 9.6 | 0.6% | Aug 19, 2025 | DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click r... |
| CVE-2025-55306 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX F... |
| CVE-2025-9149 | CRITICAL | 9.8 | 5.6% | Aug 19, 2025 | A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cg... |
| CVE-2025-55294 | CRITICAL | 9.8 | 1.5% | Aug 19, 2025 | screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue.... |
| CVE-2025-54336 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed b... |
| CVE-2025-50567 | CRITICAL | 10 | 0.7% | Aug 19, 2025 | Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replac... |
| CVE-2025-8723 | CRITICAL | 9.8 | 14.0% | Aug 19, 2025 | The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication ... |
| CVE-2025-6758 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the... |
| CVE-2025-55591 | CRITICAL | 9.8 | 7.2% | Aug 18, 2025 | TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac param... |
| CVE-2025-55213 | CRITICAL | 9.8 | 0.3% | Aug 18, 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
| CVE-2025-7693 | CRITICAL | 9.3 | 0.3% | Aug 18, 2025 | A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller e... |
| CVE-2025-55299 | CRITICAL | 9.4 | 0.2% | Aug 18, 2025 | VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through ... |
| CVE-2025-55293 | CRITICAL | 9.8 | 0.4% | Aug 18, 2025 | Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publi... |
| CVE-2025-55205 | CRITICAL | 9 | 0.4% | Aug 18, 2025 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsu... |
| CVE-2025-27909 | CRITICAL | 9.8 | 0.2% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carr... |
| CVE-2025-31715 | CRITICAL | 9.8 | 1.6% | Aug 18, 2025 | In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote esc... |
| CVE-2025-9090 | CRITICAL | 9.8 | 14.1% | Aug 17, 2025 | A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/te... |
| CVE-2025-9089 | CRITICAL | 9.8 | 1.0% | Aug 17, 2025 | A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform... |
| CVE-2025-9088 | CRITICAL | 9.8 | 0.8% | Aug 16, 2025 | A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function save_virtualser_data of the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now