2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8731 | CRITICAL | 9.8 | 0.6% | Aug 8, 2025 | A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown par... |
| CVE-2025-8356 | CRITICAL | 9.8 | 14.7% | Aug 8, 2025 | In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized file... |
| CVE-2025-8730 | CRITICAL | 9.8 | 3.0% | Aug 8, 2025 | A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this iss... |
| CVE-2025-8729 | CRITICAL | 9.1 | 0.7% | Aug 8, 2025 | A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is t... |
| CVE-2025-53606 | CRITICAL | 9.8 | 0.6% | Aug 8, 2025 | Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubati... |
| CVE-2025-48913 | CRITICAL | 9.8 | 0.7% | Aug 8, 2025 | If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially ... |
| CVE-2025-54887 | CRITICAL | 9.1 | 0.2% | Aug 8, 2025 | jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentica... |
| CVE-2025-54952 | CRITICAL | 9.8 | 0.6% | Aug 8, 2025 | An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to ... |
| CVE-2025-54951 | CRITICAL | 9.8 | 0.6% | Aug 7, 2025 | A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash an... |
| CVE-2025-54950 | CRITICAL | 9.8 | 0.6% | Aug 7, 2025 | An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially... |
| CVE-2025-54949 | CRITICAL | 9.8 | 0.6% | Aug 7, 2025 | A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or oth... |
| CVE-2025-30405 | CRITICAL | 9.8 | 0.6% | Aug 7, 2025 | An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their alloc... |
| CVE-2025-30404 | CRITICAL | 9.8 | 0.6% | Aug 7, 2025 | An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially res... |
| CVE-2025-53792 | CRITICAL | 9.1 | 0.7% | Aug 7, 2025 | Azure Portal Elevation of Privilege Vulnerability |
| CVE-2025-53767 | CRITICAL | 10 | 1.0% | Aug 7, 2025 | Azure OpenAI Elevation of Privilege Vulnerability |
| CVE-2025-45765 | CRITICAL | 9.1 | 0.2% | Aug 7, 2025 | ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not som... |
| CVE-2025-50692 | CRITICAL | 9.8 | 0.6% | Aug 7, 2025 | FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html. |
| CVE-2025-34152 | CRITICAL | 9.4 | 61.7% | Aug 7, 2025 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ... |
| CVE-2025-34151 | CRITICAL | 9.4 | 3.8% | Aug 7, 2025 | A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M30... |
| CVE-2025-34150 | CRITICAL | 9.4 | 1.4% | Aug 7, 2025 | The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to comm... |
| CVE-2025-34149 | CRITICAL | 9.4 | 1.5% | Aug 7, 2025 | A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 conf... |
| CVE-2025-34148 | CRITICAL | 9.4 | 1.3% | Aug 7, 2025 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ... |
| CVE-2025-7768 | CRITICAL | 9.3 | 0.5% | Aug 6, 2025 | Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain ... |
| CVE-2025-30127 | CRITICAL | 9.8 | 0.4% | Aug 6, 2025 | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or c... |
| CVE-2025-3354 | CRITICAL | 9.8 | 0.5% | Aug 6, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now