2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51675 | HIGH | 7.5 | 0.3% | Aug 26, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR c... |
| CVE-2025-61164 | HIGH | 7.5 | 0.3% | Aug 26, 2026 | Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. |
| CVE-2025-61162 | HIGH | 7.5 | 0.2% | Aug 26, 2026 | Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req... |
| CVE-2025-56798 | HIGH | 8.8 | 0.2% | Aug 26, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows ... |
| CVE-2025-29419 | HIGH | 7.1 | 0.2% | Aug 26, 2026 | CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack. |
| CVE-2025-26238 | HIGH | 8.1 | — | Aug 24, 2026 | In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. |
| CVE-2025-26237 | HIGH | 8.1 | — | Aug 24, 2026 | D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b... |
| CVE-2025-36940 | HIGH | 8.8 | — | Aug 24, 2026 | Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U... |
| CVE-2025-68825 | HIGH | 7.5 | — | Aug 24, 2026 | HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta... |
| CVE-2025-63080 | HIGH | 8.5 | — | Aug 24, 2026 | Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform o... |
| CVE-2025-52182 | HIGH | 7.5 | — | Aug 20, 2026 | The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability. |
| CVE-2025-15637 | HIGH | 8.1 | — | Aug 20, 2026 | Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. |
| CVE-2025-14601 | HIGH | 8.6 | — | Aug 20, 2026 | An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execu... |
| CVE-2025-36255 | HIGH | 8.8 | — | Aug 19, 2026 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authe... |
| CVE-2025-36254 | HIGH | 7.4 | — | Aug 19, 2026 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attac... |
| CVE-2025-14603 | HIGH | 8.8 | — | Aug 19, 2026 | The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable ... |
| CVE-2025-9210 | HIGH | 8.1 | — | Aug 18, 2026 | Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows ... |
| CVE-2025-27772 | HIGH | 7.4 | — | Aug 17, 2026 | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `... |
| CVE-2025-27771 | HIGH | 7.4 | — | Aug 17, 2026 | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `... |
| CVE-2025-27770 | HIGH | 7.4 | — | Aug 17, 2026 | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `... |
| CVE-2025-27621 | HIGH | 7.7 | — | Aug 17, 2026 | UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the U... |
| CVE-2025-7639 | HIGH | 7.1 | — | Aug 14, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to ta... |
| CVE-2025-59323 | HIGH | 8.4 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partition... |
| CVE-2025-59322 | HIGH | 7.5 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted v... |
| CVE-2025-59319 | HIGH | 7.2 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now