2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55422 | HIGH | 8.8 | 0.4% | Aug 27, 2025 | In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus. |
| CVE-2025-51667 | HIGH | 7 | 0.2% | Aug 27, 2025 | An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-... |
| CVE-2025-50979 | HIGH | 8.6 | 8.1% | Aug 27, 2025 | NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The sear... |
| CVE-2025-34161 | HIGH | 8.8 | 3.7% | Aug 27, 2025 | Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deplo... |
| CVE-2025-34159 | HIGH | 8.8 | 0.9% | Aug 27, 2025 | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application d... |
| CVE-2025-20344 | HIGH | 7.2 | 0.5% | Aug 27, 2025 | A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attack... |
| CVE-2025-20317 | HIGH | 7.1 | 0.5% | Aug 27, 2025 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll... |
| CVE-2025-20241 | HIGH | 7.4 | 0.3% | Aug 27, 2025 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexu... |
| CVE-2025-50983 | HIGH | 8.3 | 0.3% | Aug 27, 2025 | SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4... |
| CVE-2025-53105 | HIGH | 7.5 | 0.3% | Aug 27, 2025 | GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that... |
| CVE-2025-9532 | HIGH | 8.8 | 0.4% | Aug 27, 2025 | A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/vi... |
| CVE-2025-9531 | HIGH | 8.8 | 0.4% | Aug 27, 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/a... |
| CVE-2025-9529 | HIGH | 7.2 | 0.5% | Aug 27, 2025 | A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include ... |
| CVE-2025-9528 | HIGH | 7.2 | 50.1% | Aug 27, 2025 | A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of th... |
| CVE-2025-9527 | HIGH | 8.8 | 1.3% | Aug 27, 2025 | A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup.... |
| CVE-2025-43882 | HIGH | 7.8 | 0.1% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged a... |
| CVE-2025-43730 | HIGH | 7.8 | 0.2% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ... |
| CVE-2025-43729 | HIGH | 7.8 | 0.1% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulner... |
| CVE-2025-9526 | HIGH | 8.8 | 1.3% | Aug 27, 2025 | A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the fil... |
| CVE-2025-9525 | HIGH | 8.8 | 1.3% | Aug 27, 2025 | A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /g... |
| CVE-2025-30064 | HIGH | 8.8 | 0.1% | Aug 27, 2025 | An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function chec... |
| CVE-2025-30038 | HIGH | 7.3 | 0.2% | Aug 27, 2025 | The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is expos... |
| CVE-2025-30037 | HIGH | 8.8 | 0.2% | Aug 27, 2025 | The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal s... |
| CVE-2025-30036 | HIGH | 8.8 | 0.1% | Aug 27, 2025 | Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the... |
| CVE-2025-57846 | HIGH | 8.5 | 0.1% | Aug 27, 2025 | Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a loc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now