2025 CVE Vulnerabilities
45,160 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52094 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via ... |
| CVE-2025-51605 | HIGH | 8.1 | 0.2% | Aug 22, 2025 | An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header v... |
| CVE-2025-50674 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaV... |
| CVE-2025-38670 | HIGH | 7.1 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_... |
| CVE-2025-38667 | HIGH | 7.8 | 0.1% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: fix potential out-of-bound write The buffer i... |
| CVE-2025-38666 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix use-after-free in AARP proxy pr... |
| CVE-2025-38662 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8365-dai-i2s: pass correct size t... |
| CVE-2025-38657 | HIGH | 7.1 | 0.1% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: mcc: prevent shift wrapping in rtw89_c... |
| CVE-2025-38656 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_st... |
| CVE-2025-38653 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: proc: use the same treatment to check proc_lseek as... |
| CVE-2025-38652 | HIGH | 7.1 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.p... |
| CVE-2025-38636 | HIGH | 7.1 | 0.1% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: rv: Use strings in da monitors tracepoints Using D... |
| CVE-2025-38627 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_... |
| CVE-2025-38620 | HIGH | 7.8 | 0.1% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: zloop: fix KASAN use-after-free of tag set When a ... |
| CVE-2025-55573 | HIGH | 8.8 | 0.4% | Aug 22, 2025 | QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2025-33120 | HIGH | 7.8 | 0.1% | Aug 22, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigure... |
| CVE-2025-38618 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It ... |
| CVE-2025-38616 | HIGH | 7.1 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS UL... |
| CVE-2025-9259 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9258 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9257 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9256 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9255 | HIGH | 8.7 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitr... |
| CVE-2025-57699 | HIGH | 8.4 | 0.2% | Aug 22, 2025 | Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted ... |
| CVE-2025-8281 | HIGH | 7.1 | 0.2% | Aug 22, 2025 | The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the pag... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now