2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25172 | HIGH | 8.1 | 0.5% | Aug 14, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-24766 | HIGH | 7.5 | 0.4% | Aug 14, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-8956 | HIGH | 8.8 | 18.1% | Aug 14, 2025 | A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/c... |
| CVE-2025-54472 | HIGH | 7.5 | 1.2% | Aug 14, 2025 | Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows atta... |
| CVE-2025-48862 | HIGH | 7.1 | 0.1% | Aug 14, 2025 | Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup fi... |
| CVE-2025-48860 | HIGH | 8 | 0.3% | Aug 14, 2025 | A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) att... |
| CVE-2025-27388 | HIGH | 8.3 | 0.4% | Aug 14, 2025 | Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user to... |
| CVE-2025-8940 | HIGH | 8.8 | 0.8% | Aug 14, 2025 | A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this vulnerability is the function strcpy of... |
| CVE-2025-8939 | HIGH | 8.8 | 0.8% | Aug 14, 2025 | A vulnerability was determined in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/Wifi... |
| CVE-2025-8937 | HIGH | 8.8 | 2.4% | Aug 14, 2025 | A vulnerability has been found in TOTOLINK N350R 1.2.3-B20130826. This vulnerability affects unknown code of the file /b... |
| CVE-2025-8931 | HIGH | 8.8 | 0.4% | Aug 14, 2025 | A vulnerability was determined in code-projects Medical Store Management System 1.0. Affected is an unknown function of ... |
| CVE-2025-8930 | HIGH | 8.8 | 0.4% | Aug 14, 2025 | A vulnerability was found in code-projects Medical Store Management System 1.0. This issue affects some unknown processi... |
| CVE-2025-55197 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads... |
| CVE-2025-55196 | HIGH | 7.1 | 0.3% | Aug 13, 2025 | External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15... |
| CVE-2025-8929 | HIGH | 8.8 | 0.4% | Aug 13, 2025 | A vulnerability has been found in code-projects Medical Store Management System 1.0. This vulnerability affects unknown ... |
| CVE-2025-8928 | HIGH | 8.8 | 0.4% | Aug 13, 2025 | A vulnerability was identified in code-projects Medical Store Management System 1.0. This affects an unknown part of the... |
| CVE-2025-43988 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers t... |
| CVE-2025-8754 | HIGH | 8.7 | 0.3% | Aug 13, 2025 | Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM z... |
| CVE-2025-50617 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046ed68 function of the cgite... |
| CVE-2025-50616 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046f984 function of the cgite... |
| CVE-2025-50615 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgite... |
| CVE-2025-23306 | HIGH | 7.8 | 0.2% | Aug 13, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an ... |
| CVE-2025-23305 | HIGH | 7.8 | 0.2% | Aug 13, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a co... |
| CVE-2025-23298 | HIGH | 7.8 | 0.7% | Aug 13, 2025 | NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker coul... |
| CVE-2025-23296 | HIGH | 7.8 | 0.6% | Aug 13, 2025 | NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component where an attacker could cause a code... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now