2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55298 | HIGH | 8.8 | 4.1% | Aug 26, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick vers... |
| CVE-2025-9491 | HIGH | 7.8 | 63.1% | Aug 26, 2025 | Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote at... |
| CVE-2025-55212 | HIGH | 7.5 | 0.9% | Aug 26, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2025-36729 | HIGH | 7.2 | 0.4% | Aug 26, 2025 | A non-primary administrator user with admin rights to the web interface but without shell access permissions can display... |
| CVE-2025-1994 | HIGH | 7.8 | 0.1% | Aug 26, 2025 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due t... |
| CVE-2025-57810 | HIGH | 7.5 | 0.7% | Aug 26, 2025 | jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage me... |
| CVE-2025-6366 | HIGH | 8.8 | 0.3% | Aug 26, 2025 | The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. T... |
| CVE-2025-52218 | HIGH | 7.5 | 0.3% | Aug 26, 2025 | SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sani... |
| CVE-2025-9483 | HIGH | 8.8 | 0.9% | Aug 26, 2025 | A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1... |
| CVE-2025-9482 | HIGH | 8.8 | 7.5% | Aug 26, 2025 | A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.... |
| CVE-2025-9481 | HIGH | 8.8 | 1.3% | Aug 26, 2025 | A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.... |
| CVE-2025-8424 | HIGH | 8.7 | 2.7% | Aug 26, 2025 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker ca... |
| CVE-2025-50753 | HIGH | 8.4 | 0.1% | Aug 26, 2025 | Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "devi... |
| CVE-2025-29992 | HIGH | 7.5 | 0.3% | Aug 26, 2025 | Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the data... |
| CVE-2025-38676 | HIGH | 7.8 | 0.4% | Aug 26, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel ... |
| CVE-2025-53419 | HIGH | 7.8 | 0.2% | Aug 26, 2025 | Delta Electronics COMMGR has Code Injection vulnerability. |
| CVE-2025-53418 | HIGH | 8.6 | 0.4% | Aug 26, 2025 | Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability. |
| CVE-2025-5931 | HIGH | 8.8 | 0.4% | Aug 26, 2025 | The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and... |
| CVE-2025-9172 | HIGH | 7.5 | 0.4% | Aug 26, 2025 | The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all versions up... |
| CVE-2025-9461 | HIGH | 7.5 | 0.3% | Aug 26, 2025 | A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/... |
| CVE-2025-9443 | HIGH | 8.8 | 0.7% | Aug 26, 2025 | A flaw has been found in Tenda CH22 1.0.0.1. This vulnerability affects the function formeditUserName of the file /gofor... |
| CVE-2025-8627 | HIGH | 8.8 | 0.3% | Aug 25, 2025 | The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off conditio... |
| CVE-2025-57809 | HIGH | 7.5 | 0.4% | Aug 25, 2025 | XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.21,... |
| CVE-2025-57805 | HIGH | 8.7 | 0.3% | Aug 25, 2025 | The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, c... |
| CVE-2025-6188 | HIGH | 7.5 | 0.4% | Aug 25, 2025 | On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. U... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now