2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3671 | HIGH | 8.8 | 0.7% | Aug 16, 2025 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u... |
| CVE-2025-55284 | HIGH | 7.5 | 0.4% | Aug 16, 2025 | Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prom... |
| CVE-2025-55286 | HIGH | 7.3 | 0.1% | Aug 16, 2025 | z2d is a pure Zig 2D graphics library. z2d v0.7.0 released with a new multi-sample anti-aliasing (MSAA) method, which us... |
| CVE-2025-52621 | HIGH | 7.5 | 0.1% | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning. The BigFix SaaS's HTTP responses were observe... |
| CVE-2025-8959 | HIGH | 7.5 | 0.5% | Aug 15, 2025 | HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized rea... |
| CVE-2025-43490 | HIGH | 8.4 | 0.1% | Aug 15, 2025 | A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support... |
| CVE-2025-8675 | HIGH | 8.8 | 0.2% | Aug 15, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This i... |
| CVE-2025-8361 | HIGH | 7.6 | 0.3% | Aug 15, 2025 | Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: f... |
| CVE-2025-8092 | HIGH | 7.6 | 0.3% | Aug 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con... |
| CVE-2025-49898 | HIGH | 7.6 | 0.4% | Aug 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix... |
| CVE-2025-49897 | HIGH | 8.8 | 0.4% | Aug 15, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical ... |
| CVE-2025-5048 | HIGH | 7.8 | 0.2% | Aug 15, 2025 | A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerabili... |
| CVE-2025-5047 | HIGH | 7.8 | 0.2% | Aug 15, 2025 | A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability.... |
| CVE-2025-5046 | HIGH | 7.8 | 0.2% | Aug 15, 2025 | A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabi... |
| CVE-2025-54989 | HIGH | 7.5 | 0.5% | Aug 15, 2025 | Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL poin... |
| CVE-2025-24975 | HIGH | 8.8 | 0.5% | Aug 15, 2025 | Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnera... |
| CVE-2025-54475 | HIGH | 8.7 | 0.3% | Aug 15, 2025 | A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execut... |
| CVE-2025-54474 | HIGH | 8.5 | 0.3% | Aug 15, 2025 | A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged use... |
| CVE-2025-1929 | HIGH | 7.2 | 0.4% | Aug 15, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Tekno... |
| CVE-2025-9046 | HIGH | 8.8 | 0.7% | Aug 15, 2025 | A vulnerability was identified in Tenda AC20 16.03.08.12. This issue affects the function sub_46A2AC of the file /goform... |
| CVE-2025-9025 | HIGH | 8.8 | 0.3% | Aug 15, 2025 | A vulnerability was determined in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown ... |
| CVE-2025-9023 | HIGH | 8.8 | 0.7% | Aug 15, 2025 | A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed o... |
| CVE-2025-7650 | HIGH | 7.5 | 0.6% | Aug 15, 2025 | The BizCalendar Web plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1... |
| CVE-2025-7641 | HIGH | 7.5 | 0.5% | Aug 15, 2025 | The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient... |
| CVE-2025-9016 | HIGH | 7 | 0.2% | Aug 15, 2025 | A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now