2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23303 | CRITICAL | 9.8 | 0.5% | Aug 13, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted... |
| CVE-2025-52385 | CRITICAL | 9.8 | 1.0% | Aug 13, 2025 | An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to ... |
| CVE-2025-51451 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginA... |
| CVE-2025-50594 | CRITICAL | 9.8 | 0.3% | Aug 13, 2025 | An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health ... |
| CVE-2025-34153 | CRITICAL | 10 | 0.6% | Aug 13, 2025 | Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code... |
| CVE-2025-51452 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through fo... |
| CVE-2025-50251 | CRITICAL | 9.1 | 0.3% | Aug 13, 2025 | Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery. |
| CVE-2025-54074 | CRITICAL | 9.8 | 2.1% | Aug 13, 2025 | Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio ... |
| CVE-2025-8908 | CRITICAL | 9.8 | 0.3% | Aug 13, 2025 | A vulnerability was determined in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. Affected by this ... |
| CVE-2025-8913 | CRITICAL | 9.8 | 0.6% | Aug 13, 2025 | Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated re... |
| CVE-2025-8760 | CRITICAL | 9.8 | 0.7% | Aug 13, 2025 | A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the co... |
| CVE-2025-6715 | CRITICAL | 9.8 | 0.5% | Aug 13, 2025 | The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes... |
| CVE-2025-7384 | CRITICAL | 9.8 | 1.6% | Aug 13, 2025 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in ... |
| CVE-2025-55168 | CRITICAL | 9.8 | 0.4% | Aug 12, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio... |
| CVE-2025-25256 | CRITICAL | 9.8 | 60.3% | Aug 12, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul... |
| CVE-2025-53766 | CRITICAL | 9.8 | 6.7% | Aug 12, 2025 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
| CVE-2025-50171 | CRITICAL | 9.1 | 0.9% | Aug 12, 2025 | Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-50165 | CRITICAL | 9.8 | 3.5% | Aug 12, 2025 | Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a net... |
| CVE-2025-55167 | CRITICAL | 9.8 | 0.5% | Aug 12, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio... |
| CVE-2025-24325 | CRITICAL | 9.3 | 0.1% | Aug 12, 2025 | Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 ma... |
| CVE-2025-3831 | CRITICAL | 9.8 | 0.4% | Aug 12, 2025 | Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties. |
| CVE-2025-8059 | CRITICAL | 9.8 | 0.4% | Aug 12, 2025 | The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input ... |
| CVE-2025-42957 | CRITICAL | 9.9 | 1.5% | Aug 12, 2025 | SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. T... |
| CVE-2025-42950 | CRITICAL | 9.9 | 0.6% | Aug 12, 2025 | SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo... |
| CVE-2025-55161 | CRITICAL | 9.8 | 1.9% | Aug 11, 2025 | Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now