2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6203 | HIGH | 7.5 | 0.7% | Aug 28, 2025 | A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit whic... |
| CVE-2025-9580 | HIGH | 8.8 | 6.7% | Aug 28, 2025 | A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform... |
| CVE-2025-9579 | HIGH | 8.8 | 6.9% | Aug 28, 2025 | A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/... |
| CVE-2025-9577 | HIGH | 7 | 0.2% | Aug 28, 2025 | A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the f... |
| CVE-2025-57215 | HIGH | 7.5 | 0.4% | Aug 28, 2025 | Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to contain a stack overflow via the function get_parentControl_list... |
| CVE-2025-9576 | HIGH | 7 | 0.2% | Aug 28, 2025 | A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is an unknown function of the file /etc/sha... |
| CVE-2025-9575 | HIGH | 8.8 | 8.4% | Aug 28, 2025 | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0... |
| CVE-2025-58049 | HIGH | 7.5 | 0.3% | Aug 28, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions fro... |
| CVE-2025-58047 | HIGH | 7.5 | 0.6% | Aug 28, 2025 | Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.... |
| CVE-2025-58335 | HIGH | 7.5 | 0.2% | Aug 28, 2025 | In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54... |
| CVE-2025-58334 | HIGH | 8.8 | 0.3% | Aug 28, 2025 | In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-p... |
| CVE-2025-57767 | HIGH | 7.5 | 0.4% | Aug 28, 2025 | Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2... |
| CVE-2025-8067 | HIGH | 8.5 | 0.7% | Aug 28, 2025 | A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system.... |
| CVE-2025-9578 | HIGH | 7.8 | 0.1% | Aug 28, 2025 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec... |
| CVE-2025-54742 | HIGH | 8.8 | 0.3% | Aug 28, 2025 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This... |
| CVE-2025-54731 | HIGH | 8.1 | 0.3% | Aug 28, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showc... |
| CVE-2025-54724 | HIGH | 7.1 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo al... |
| CVE-2025-54716 | HIGH | 8.1 | 0.4% | Aug 28, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-54714 | HIGH | 7.1 | 0.2% | Aug 28, 2025 | Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incor... |
| CVE-2025-54710 | HIGH | 7.1 | 0.2% | Aug 28, 2025 | Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Co... |
| CVE-2025-54029 | HIGH | 7.7 | 0.4% | Aug 28, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce cs... |
| CVE-2025-53588 | HIGH | 7.7 | 0.4% | Aug 28, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR S... |
| CVE-2025-53584 | HIGH | 8.1 | 0.3% | Aug 28, 2025 | Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket S... |
| CVE-2025-53583 | HIGH | 8.1 | 0.3% | Aug 28, 2025 | Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight allows Object In... |
| CVE-2025-53579 | HIGH | 7.1 | 0.2% | Aug 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captcha.eu Captcha... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now