2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8420 | HIGH | 8.1 | 0.9% | Aug 6, 2025 | Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code ... |
| CVE-2025-54635 | HIGH | 7.5 | 0.1% | Aug 6, 2025 | Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of... |
| CVE-2025-54630 | HIGH | 7.5 | 0.2% | Aug 6, 2025 | :Vulnerability of insufficient data length verification in the DFA module. Impact: Successful exploitation of this vulne... |
| CVE-2025-54628 | HIGH | 7.5 | 0.2% | Aug 6, 2025 | Vulnerability of incomplete verification information in the communication module. Impact: Successful exploitation of thi... |
| CVE-2025-54627 | HIGH | 8.8 | 0.2% | Aug 6, 2025 | Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect s... |
| CVE-2025-8654 | HIGH | 8.8 | 0.8% | Aug 6, 2025 | Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-a... |
| CVE-2025-8653 | HIGH | 8.8 | 0.4% | Aug 6, 2025 | Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-7036 | HIGH | 7.5 | 0.5% | Aug 6, 2025 | The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all vers... |
| CVE-2025-54622 | HIGH | 7.4 | 0.1% | Aug 6, 2025 | Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnera... |
| CVE-2025-54610 | HIGH | 7.5 | 0.2% | Aug 6, 2025 | Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2025-54609 | HIGH | 7.5 | 0.2% | Aug 6, 2025 | Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2025-54607 | HIGH | 7.5 | 0.2% | Aug 6, 2025 | Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2025-54606 | HIGH | 7.1 | 0.1% | Aug 6, 2025 | Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will ... |
| CVE-2025-54655 | HIGH | 7.8 | 0.1% | Aug 6, 2025 | Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect... |
| CVE-2025-54884 | HIGH | 8.7 | 0.3% | Aug 6, 2025 | Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and be... |
| CVE-2025-54879 | HIGH | 7.5 | 0.5% | Aug 6, 2025 | Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration... |
| CVE-2025-54872 | HIGH | 8.7 | 0.3% | Aug 6, 2025 | onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd... |
| CVE-2025-54801 | HIGH | 7.5 | 0.3% | Aug 6, 2025 | Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParse... |
| CVE-2025-53534 | HIGH | 7.7 | 0.6% | Aug 5, 2025 | RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obta... |
| CVE-2025-51628 | HIGH | 7.5 | 0.4% | Aug 5, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and be... |
| CVE-2025-7674 | HIGH | 7.1 | 0.3% | Aug 5, 2025 | Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input da... |
| CVE-2025-54254 | HIGH | 8.6 | 85.5% | Aug 5, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Refe... |
| CVE-2025-43978 | HIGH | 7.4 | 1.1% | Aug 5, 2025 | Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vul... |
| CVE-2025-43979 | HIGH | 7.4 | 5.0% | Aug 5, 2025 | An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute ar... |
| CVE-2025-29745 | HIGH | 7.5 | 0.4% | Aug 5, 2025 | A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote ser... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now