2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7033 | HIGH | 7.8 | 0.3% | Aug 5, 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re... |
| CVE-2025-7032 | HIGH | 7.8 | 0.3% | Aug 5, 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re... |
| CVE-2025-7025 | HIGH | 7.8 | 0.3% | Aug 5, 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re... |
| CVE-2025-6207 | HIGH | 8.8 | 0.6% | Aug 5, 2025 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2025-5061 | HIGH | 8.8 | 0.6% | Aug 5, 2025 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2025-41698 | HIGH | 7.8 | 0.1% | Aug 5, 2025 | A low privileged local attacker can interact with the affected service although user-interaction should not be allowed. |
| CVE-2025-7050 | HIGH | 7.2 | 0.3% | Aug 5, 2025 | The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-54868 | HIGH | 7.5 | 0.4% | Aug 5, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint ... |
| CVE-2025-54871 | HIGH | 7.8 | 0.2% | Aug 5, 2025 | Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app... |
| CVE-2025-54870 | HIGH | 8.7 | 0.2% | Aug 5, 2025 | VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules ... |
| CVE-2025-54803 | HIGH | 7.5 | 0.5% | Aug 5, 2025 | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype ... |
| CVE-2025-54780 | HIGH | 7.7 | 0.3% | Aug 5, 2025 | The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2... |
| CVE-2025-53544 | HIGH | 7.5 | 0.3% | Aug 5, 2025 | Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person... |
| CVE-2025-8530 | HIGH | 7.5 | 0.4% | Aug 4, 2025 | A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue... |
| CVE-2025-46093 | HIGH | 8.8 | 0.5% | Aug 4, 2025 | LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execut... |
| CVE-2025-27211 | HIGH | 7.5 | 0.6% | Aug 4, 2025 | An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a mal... |
| CVE-2025-8527 | HIGH | 8.8 | 0.3% | Aug 4, 2025 | A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown pr... |
| CVE-2025-51726 | HIGH | 8.4 | 0.1% | Aug 4, 2025 | CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnera... |
| CVE-2025-53395 | HIGH | 7.7 | 0.2% | Aug 4, 2025 | Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privile... |
| CVE-2025-53394 | HIGH | 7.7 | 0.1% | Aug 4, 2025 | Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges vi... |
| CVE-2025-38741 | HIGH | 7.5 | 0.4% | Aug 4, 2025 | Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote at... |
| CVE-2025-8518 | HIGH | 7.2 | 1.3% | Aug 4, 2025 | A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function S... |
| CVE-2025-51534 | HIGH | 8.1 | 0.4% | Aug 4, 2025 | A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers ... |
| CVE-2025-44963 | HIGH | 8.1 | 0.6% | Aug 4, 2025 | RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded ... |
| CVE-2025-44961 | HIGH | 8.8 | 2.1% | Aug 4, 2025 | In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now