2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55299 | CRITICAL | 9.4 | 0.2% | Aug 18, 2025 | VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through ... |
| CVE-2025-55293 | CRITICAL | 9.8 | 0.4% | Aug 18, 2025 | Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publi... |
| CVE-2025-55205 | CRITICAL | 9 | 0.4% | Aug 18, 2025 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsu... |
| CVE-2025-27909 | CRITICAL | 9.8 | 0.2% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carr... |
| CVE-2025-31715 | CRITICAL | 9.8 | 1.6% | Aug 18, 2025 | In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote esc... |
| CVE-2025-9090 | CRITICAL | 9.8 | 14.1% | Aug 17, 2025 | A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/te... |
| CVE-2025-9089 | CRITICAL | 9.8 | 1.0% | Aug 17, 2025 | A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform... |
| CVE-2025-9088 | CRITICAL | 9.8 | 0.8% | Aug 16, 2025 | A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function save_virtualser_data of the... |
| CVE-2025-9087 | CRITICAL | 9.8 | 1.0% | Aug 16, 2025 | A vulnerability has been found in Tenda AC20 16.03.08.12. This affects the function set_qosMib_list of the file /goform/... |
| CVE-2025-8898 | CRITICAL | 9.8 | 0.4% | Aug 16, 2025 | The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account ... |
| CVE-2025-7441 | CRITICAL | 9.8 | 37.3% | Aug 16, 2025 | The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42... |
| CVE-2025-52618 | CRITICAL | 9.8 | 0.3% | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential... |
| CVE-2025-9060 | CRITICAL | 9.1 | 0.5% | Aug 15, 2025 | A vulnerability has been found in the MSoft MFlash application that allows execution of arbitrary code on the server... |
| CVE-2025-8995 | CRITICAL | 9.8 | 0.5% | Aug 15, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati... |
| CVE-2025-54466 | CRITICAL | 9.8 | 14.0% | Aug 15, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum ... |
| CVE-2025-9053 | CRITICAL | 9.8 | 0.4% | Aug 15, 2025 | A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of... |
| CVE-2025-9052 | CRITICAL | 9.8 | 0.4% | Aug 15, 2025 | A vulnerability was identified in projectworlds Travel Management System 1.0. This affects an unknown part of the file /... |
| CVE-2025-9051 | CRITICAL | 9.8 | 0.4% | Aug 15, 2025 | A vulnerability was determined in projectworlds Travel Management System 1.0. Affected by this issue is some unknown fun... |
| CVE-2025-9050 | CRITICAL | 9.8 | 0.4% | Aug 15, 2025 | A vulnerability was found in projectworlds Travel Management System 1.0. Affected by this vulnerability is an unknown fu... |
| CVE-2025-54473 | CRITICAL | 9.2 | 0.4% | Aug 15, 2025 | An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. T... |
| CVE-2025-9047 | CRITICAL | 9.8 | 0.4% | Aug 15, 2025 | A vulnerability has been found in projectworlds Visitor Management System 1.0. Affected is an unknown function of the fi... |
| CVE-2025-9028 | CRITICAL | 9.8 | 0.4% | Aug 15, 2025 | A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /a... |
| CVE-2025-9027 | CRITICAL | 9.8 | 0.5% | Aug 15, 2025 | A vulnerability has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of th... |
| CVE-2025-9026 | CRITICAL | 9.8 | 3.9% | Aug 15, 2025 | A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cg... |
| CVE-2025-9024 | CRITICAL | 9.8 | 0.4% | Aug 15, 2025 | A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unkno... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now