2025 CVE Vulnerabilities
45,124 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31936 | HIGH | 7 | — | Aug 11, 2026 | Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) ... |
| CVE-2025-31356 | MEDIUM | 5.6 | — | Aug 11, 2026 | Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: H... |
| CVE-2025-0041 | MEDIUM | 4.6 | — | Aug 11, 2026 | Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a... |
| CVE-2025-31114 | CRITICAL | 9.3 | — | Aug 11, 2026 | Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code ex... |
| CVE-2025-30241 | HIGH | 8.6 | — | Aug 10, 2026 | Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input pro... |
| CVE-2025-30240 | MEDIUM | 5.1 | — | Aug 10, 2026 | The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By ... |
| CVE-2025-30239 | HIGH | 8.5 | 0.1% | Aug 10, 2026 | In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive co... |
| CVE-2025-30238 | HIGH | 8.6 | 0.1% | Aug 10, 2026 | In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to e... |
| CVE-2025-30237 | HIGH | 8.7 | 0.2% | Aug 10, 2026 | The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not c... |
| CVE-2025-32736 | MEDIUM | 4.9 | 0.2% | Aug 10, 2026 | Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may all... |
| CVE-2025-15683 | HIGH | 8.8 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An ... |
| CVE-2025-15682 | HIGH | 8.7 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauth... |
| CVE-2025-15681 | CRITICAL | 9.2 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic... |
| CVE-2025-15680 | LOW | 2.4 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph... |
| CVE-2025-13294 | CRITICAL | 9.3 | — | Aug 10, 2026 | An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP ... |
| CVE-2025-13293 | CRITICAL | 9.3 | — | Aug 10, 2026 | A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attack... |
| CVE-2025-4438 | — | — | — | Aug 7, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-71413 | MEDIUM | 6 | 0.2% | Aug 7, 2026 | Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w... |
| CVE-2025-71412 | HIGH | 7.1 | 0.2% | Aug 7, 2026 | Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion... |
| CVE-2025-71411 | MEDIUM | 6 | 0.2% | Aug 7, 2026 | Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic c... |
| CVE-2025-71410 | MEDIUM | 6 | 0.2% | Aug 7, 2026 | Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and... |
| CVE-2025-71409 | HIGH | 7.1 | 0.2% | Aug 7, 2026 | Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages ... |
| CVE-2025-63235 | HIGH | 7.5 | — | Aug 7, 2026 | In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON... |
| CVE-2025-6508 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b... |
| CVE-2025-15674 | LOW | 2.7 | 0.2% | Aug 6, 2026 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now