2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55587 | HIGH | 7.5 | 0.4% | Aug 18, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/f... |
| CVE-2025-55586 | HIGH | 7.5 | 0.4% | Aug 18, 2025 | TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFi... |
| CVE-2025-53192 | HIGH | 8.8 | 0.5% | Aug 18, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons... |
| CVE-2025-4371 | HIGH | 7 | 0.2% | Aug 18, 2025 | A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacke... |
| CVE-2025-32992 | HIGH | 8.5 | 0.2% | Aug 18, 2025 | Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control. |
| CVE-2025-55300 | HIGH | 8.6 | 0.5% | Aug 18, 2025 | Komari is a lightweight, self-hosted server monitoring tool designed to provide a simple and efficient solution for moni... |
| CVE-2025-55291 | HIGH | 7.1 | 0.2% | Aug 18, 2025 | Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag pa... |
| CVE-2025-55283 | HIGH | 7.2 | 0.6% | Aug 18, 2025 | aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that... |
| CVE-2025-55282 | HIGH | 7.2 | 0.7% | Aug 18, 2025 | aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that... |
| CVE-2025-55201 | HIGH | 8.5 | 0.2% | Aug 18, 2025 | Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write... |
| CVE-2025-4962 | HIGH | 7.7 | 0.2% | Aug 18, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Luna... |
| CVE-2025-36120 | HIGH | 8.8 | 0.3% | Aug 18, 2025 | IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH s... |
| CVE-2025-33100 | HIGH | 7.5 | 0.2% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, whi... |
| CVE-2025-33090 | HIGH | 7.5 | 0.4% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially cr... |
| CVE-2025-1759 | HIGH | 7.5 | 0.3% | Aug 18, 2025 | IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated me... |
| CVE-2025-47206 | HIGH | 8.1 | 0.4% | Aug 18, 2025 | An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accou... |
| CVE-2025-5296 | HIGH | 7.3 | 0.2% | Aug 18, 2025 | CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary ... |
| CVE-2025-6625 | HIGH | 8.7 | 0.5% | Aug 18, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP co... |
| CVE-2025-31713 | HIGH | 8.4 | 0.7% | Aug 18, 2025 | In engineer mode service, there is a possible command injection due to improper input validation. This could lead to loc... |
| CVE-2025-7342 | HIGH | 7.5 | 0.3% | Aug 17, 2025 | A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows... |
| CVE-2025-9091 | HIGH | 7.8 | 0.2% | Aug 17, 2025 | A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionalit... |
| CVE-2025-8142 | HIGH | 8.8 | 0.5% | Aug 16, 2025 | The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via th... |
| CVE-2025-8105 | HIGH | 7.3 | 0.3% | Aug 16, 2025 | The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,... |
| CVE-2025-38552 | HIGH | 7.8 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: mptcp: plug races between subflow fail and subflow ... |
| CVE-2025-38550 | HIGH | 7.8 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec(... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now