2025 CVE Vulnerabilities
45,169 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46709 | HIGH | 7.5 | 0.3% | Aug 9, 2025 | Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kern... |
| CVE-2025-4796 | HIGH | 8.8 | 0.5% | Aug 8, 2025 | The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i... |
| CVE-2025-52914 | HIGH | 8.8 | 0.6% | Aug 8, 2025 | A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could a... |
| CVE-2025-8393 | HIGH | 8.5 | 0.1% | Aug 8, 2025 | A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts se... |
| CVE-2025-53520 | HIGH | 8.8 | 0.2% | Aug 8, 2025 | The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or insta... |
| CVE-2025-50465 | HIGH | 8.8 | 0.3% | Aug 8, 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l... |
| CVE-2025-8355 | HIGH | 7.5 | 6.9% | Aug 8, 2025 | In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker ... |
| CVE-2025-52586 | HIGH | 7.5 | 0.1% | Aug 8, 2025 | The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryp... |
| CVE-2025-36119 | HIGH | 8.8 | 0.2% | Aug 8, 2025 | IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certifi... |
| CVE-2025-8088 | HIGH | 8.8 | 94.6% | Aug 8, 2025 | A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by... |
| CVE-2025-8748 | HIGH | 8.8 | 1.3% | Aug 8, 2025 | MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP reques... |
| CVE-2025-8708 | HIGH | 7.5 | 0.4% | Aug 8, 2025 | A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the... |
| CVE-2025-8706 | HIGH | 8.8 | 0.3% | Aug 8, 2025 | A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as criti... |
| CVE-2025-8705 | HIGH | 8.8 | 0.3% | Aug 8, 2025 | A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving Syst... |
| CVE-2025-8704 | HIGH | 8.8 | 0.3% | Aug 8, 2025 | A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving... |
| CVE-2025-8703 | HIGH | 8.8 | 0.3% | Aug 8, 2025 | A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This... |
| CVE-2025-54886 | HIGH | 8.4 | 0.2% | Aug 8, 2025 | skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below... |
| CVE-2025-8702 | HIGH | 8.8 | 0.3% | Aug 8, 2025 | A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0.... |
| CVE-2025-8701 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critic... |
| CVE-2025-53787 | HIGH | 7.5 | 0.6% | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
| CVE-2025-53774 | HIGH | 7.5 | 0.5% | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
| CVE-2025-26513 | HIGH | 7.8 | 0.1% | Aug 7, 2025 | The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when succ... |
| CVE-2025-48709 | HIGH | 7.8 | 0.1% | Aug 7, 2025 | BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated atta... |
| CVE-2025-47219 | HIGH | 8.1 | 0.6% | Aug 7, 2025 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer whil... |
| CVE-2025-55077 | HIGH | 7.4 | 0.2% | Aug 7, 2025 | Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now