2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43982 | CRITICAL | 9.8 | 0.3% | Aug 13, 2025 | Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden ... |
| CVE-2025-8925 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | A vulnerability has been found in itsourcecode Sports Management System 1.0. Affected is an unknown function of the file... |
| CVE-2025-8924 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | A vulnerability was identified in Campcodes Online Water Billing System 1.0. This issue affects some unknown processing ... |
| CVE-2025-8923 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | A vulnerability was determined in code-projects Job Diary 1.0. This vulnerability affects unknown code of the file /edit... |
| CVE-2025-8922 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | A vulnerability was found in code-projects Job Diary 1.0. This affects an unknown part of the file /admin-inbox.php. The... |
| CVE-2025-8921 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | A vulnerability has been found in code-projects Job Diary 1.0. Affected by this issue is some unknown functionality of t... |
| CVE-2025-8904 | CRITICAL | 9 | 0.3% | Aug 13, 2025 | Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ director... |
| CVE-2025-23304 | CRITICAL | 9.8 | 1.0% | Aug 13, 2025 | NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could c... |
| CVE-2025-23303 | CRITICAL | 9.8 | 0.5% | Aug 13, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted... |
| CVE-2025-52385 | CRITICAL | 9.8 | 1.0% | Aug 13, 2025 | An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to ... |
| CVE-2025-51451 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginA... |
| CVE-2025-50594 | CRITICAL | 9.8 | 0.3% | Aug 13, 2025 | An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health ... |
| CVE-2025-34153 | CRITICAL | 10 | 0.6% | Aug 13, 2025 | Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code... |
| CVE-2025-51452 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through fo... |
| CVE-2025-50251 | CRITICAL | 9.1 | 0.3% | Aug 13, 2025 | Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery. |
| CVE-2025-54074 | CRITICAL | 9.8 | 2.1% | Aug 13, 2025 | Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio ... |
| CVE-2025-8908 | CRITICAL | 9.8 | 0.3% | Aug 13, 2025 | A vulnerability was determined in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. Affected by this ... |
| CVE-2025-8913 | CRITICAL | 9.8 | 0.6% | Aug 13, 2025 | Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated re... |
| CVE-2025-8760 | CRITICAL | 9.8 | 0.7% | Aug 13, 2025 | A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the co... |
| CVE-2025-6715 | CRITICAL | 9.8 | 0.5% | Aug 13, 2025 | The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes... |
| CVE-2025-7384 | CRITICAL | 9.8 | 1.6% | Aug 13, 2025 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in ... |
| CVE-2025-55168 | CRITICAL | 9.8 | 0.4% | Aug 12, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio... |
| CVE-2025-25256 | CRITICAL | 9.8 | 56.2% | Aug 12, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2025-53766 | CRITICAL | 9.8 | 6.7% | Aug 12, 2025 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
| CVE-2025-50171 | CRITICAL | 9.1 | 0.9% | Aug 12, 2025 | Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now