2025 CVE Vulnerabilities
45,334 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55732 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injecti... |
| CVE-2025-55731 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would nor... |
| CVE-2025-55498 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime fu... |
| CVE-2025-55482 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function. |
| CVE-2025-51991 | HIGH | 8.8 | 3.4% | Aug 20, 2025 | XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, spe... |
| CVE-2025-36114 | HIGH | 7.5 | 0.5% | Aug 20, 2025 | IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An a... |
| CVE-2025-55503 | HIGH | 7.3 | 0.3% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInf... |
| CVE-2025-55483 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters mac... |
| CVE-2025-54926 | HIGH | 7.2 | 0.8% | Aug 20, 2025 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c... |
| CVE-2025-54925 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data ... |
| CVE-2025-54924 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data ... |
| CVE-2025-54923 | HIGH | 8.7 | 0.6% | Aug 20, 2025 | CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of... |
| CVE-2025-50503 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the O... |
| CVE-2025-30256 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A spe... |
| CVE-2025-24496 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.1... |
| CVE-2025-8453 | HIGH | 8.4 | 0.2% | Aug 20, 2025 | CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code exe... |
| CVE-2025-57729 | HIGH | 7.3 | 0.1% | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start |
| CVE-2025-57727 | HIGH | 7.5 | 0.2% | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference |
| CVE-2025-5261 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Ex... |
| CVE-2025-5260 | HIGH | 8.6 | 0.3% | Aug 20, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Server Side Requ... |
| CVE-2025-55715 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows... |
| CVE-2025-54750 | HIGH | 7.5 | 0.5% | Aug 20, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-54735 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This i... |
| CVE-2025-54677 | HIGH | 7.2 | 0.4% | Aug 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPres... |
| CVE-2025-54670 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now