2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7654 | HIGH | 8.8 | 0.6% | Aug 19, 2025 | Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes ... |
| CVE-2025-8218 | HIGH | 8.8 | 0.3% | Aug 19, 2025 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the... |
| CVE-2025-54156 | HIGH | 7.5 | 0.2% | Aug 18, 2025 | The Sante PACS Server Web Portal sends credential information without encryption. |
| CVE-2025-53948 | HIGH | 8.7 | 0.7% | Aug 18, 2025 | The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a deni... |
| CVE-2025-52584 | HIGH | 8.4 | 0.2% | Aug 18, 2025 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati... |
| CVE-2025-46269 | HIGH | 8.4 | 0.2% | Aug 18, 2025 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati... |
| CVE-2025-53705 | HIGH | 8.4 | 0.2% | Aug 18, 2025 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati... |
| CVE-2025-41392 | HIGH | 8.4 | 0.2% | Aug 18, 2025 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati... |
| CVE-2025-8098 | HIGH | 8.5 | 0.1% | Aug 18, 2025 | An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate pri... |
| CVE-2025-55588 | HIGH | 7.5 | 0.4% | Aug 18, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/form... |
| CVE-2025-55587 | HIGH | 7.5 | 0.4% | Aug 18, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/f... |
| CVE-2025-55586 | HIGH | 7.5 | 0.4% | Aug 18, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFi... |
| CVE-2025-53192 | HIGH | 8.8 | 0.5% | Aug 18, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons... |
| CVE-2025-4371 | HIGH | 7 | 0.2% | Aug 18, 2025 | A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacke... |
| CVE-2025-32992 | HIGH | 8.5 | 0.2% | Aug 18, 2025 | Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control. |
| CVE-2025-55300 | HIGH | 8.6 | 0.5% | Aug 18, 2025 | Komari is a lightweight, self-hosted server monitoring tool designed to provide a simple and efficient solution for moni... |
| CVE-2025-55291 | HIGH | 7.1 | 0.2% | Aug 18, 2025 | Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag pa... |
| CVE-2025-55283 | HIGH | 7.2 | 0.6% | Aug 18, 2025 | aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that... |
| CVE-2025-55282 | HIGH | 7.2 | 0.7% | Aug 18, 2025 | aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that... |
| CVE-2025-55201 | HIGH | 8.5 | 0.2% | Aug 18, 2025 | Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write... |
| CVE-2025-4962 | HIGH | 7.7 | 0.2% | Aug 18, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Luna... |
| CVE-2025-36120 | HIGH | 8.8 | 0.3% | Aug 18, 2025 | IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH s... |
| CVE-2025-33100 | HIGH | 7.5 | 0.2% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, whi... |
| CVE-2025-33090 | HIGH | 7.5 | 0.4% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially cr... |
| CVE-2025-1759 | HIGH | 7.5 | 0.3% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now