2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2611 | CRITICAL | 9.3 | 6.1% | Aug 5, 2025 | The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject she... |
| CVE-2025-54987 | CRITICAL | 9.8 | 16.9% | Aug 5, 2025 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ... |
| CVE-2025-54948 | CRITICAL | 9.8 | 20.3% | Aug 5, 2025 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ... |
| CVE-2025-54982 | CRITICAL | 9.6 | 0.4% | Aug 5, 2025 | An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowe... |
| CVE-2025-53417 | CRITICAL | 9.3 | 10.9% | Aug 5, 2025 | DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability |
| CVE-2025-8535 | CRITICAL | 9 | 0.4% | Aug 5, 2025 | A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects... |
| CVE-2025-54865 | CRITICAL | 9.8 | 0.4% | Aug 5, 2025 | Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missin... |
| CVE-2025-54802 | CRITICAL | 9.8 | 1.1% | Aug 5, 2025 | pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there i... |
| CVE-2025-54795 | CRITICAL | 9.8 | 0.9% | Aug 5, 2025 | Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass... |
| CVE-2025-54794 | CRITICAL | 9.1 | 0.9% | Aug 5, 2025 | Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead o... |
| CVE-2025-54387 | CRITICAL | 9.8 | 0.6% | Aug 5, 2025 | IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 throu... |
| CVE-2025-54135 | CRITICAL | 9.8 | 1.7% | Aug 5, 2025 | Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in... |
| CVE-2025-54130 | CRITICAL | 9.8 | 0.3% | Aug 5, 2025 | Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in... |
| CVE-2025-54119 | CRITICAL | 10 | 0.5% | Aug 5, 2025 | ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versi... |
| CVE-2025-27212 | CRITICAL | 9.8 | 1.2% | Aug 4, 2025 | An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with a... |
| CVE-2025-8526 | CRITICAL | 9.8 | 0.3% | Aug 4, 2025 | A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the ... |
| CVE-2025-51387 | CRITICAL | 9.8 | 0.5% | Aug 4, 2025 | The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifical... |
| CVE-2025-50754 | CRITICAL | 9.6 | 0.5% | Aug 4, 2025 | Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A mali... |
| CVE-2025-50341 | CRITICAL | 9.8 | 0.4% | Aug 4, 2025 | A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can ma... |
| CVE-2025-52239 | CRITICAL | 9.8 | 0.4% | Aug 4, 2025 | An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file. |
| CVE-2025-51390 | CRITICAL | 9.8 | 2.2% | Aug 4, 2025 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter... |
| CVE-2025-34147 | CRITICAL | 9.4 | 1.1% | Aug 4, 2025 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ... |
| CVE-2025-51535 | CRITICAL | 9.1 | 0.4% | Aug 4, 2025 | Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability. |
| CVE-2025-44954 | CRITICAL | 9.8 | 0.7% | Aug 4, 2025 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account. |
| CVE-2025-51536 | CRITICAL | 9.8 | 0.5% | Aug 4, 2025 | Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now