2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7050 | HIGH | 7.2 | 0.3% | Aug 5, 2025 | The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-54868 | HIGH | 7.5 | 0.4% | Aug 5, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint ... |
| CVE-2025-54871 | HIGH | 7.8 | 0.2% | Aug 5, 2025 | Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app... |
| CVE-2025-54870 | HIGH | 8.7 | 0.2% | Aug 5, 2025 | VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules ... |
| CVE-2025-54803 | HIGH | 7.5 | 0.5% | Aug 5, 2025 | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype ... |
| CVE-2025-54780 | HIGH | 7.7 | 0.3% | Aug 5, 2025 | The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2... |
| CVE-2025-53544 | HIGH | 7.5 | 0.3% | Aug 5, 2025 | Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person... |
| CVE-2025-8530 | HIGH | 7.5 | 0.4% | Aug 4, 2025 | A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue... |
| CVE-2025-46093 | HIGH | 8.8 | 0.5% | Aug 4, 2025 | LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execut... |
| CVE-2025-27211 | HIGH | 7.5 | 0.6% | Aug 4, 2025 | An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a mal... |
| CVE-2025-8527 | HIGH | 8.8 | 0.3% | Aug 4, 2025 | A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown pr... |
| CVE-2025-51726 | HIGH | 8.4 | 0.1% | Aug 4, 2025 | CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnera... |
| CVE-2025-53395 | HIGH | 7.7 | 0.2% | Aug 4, 2025 | Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privile... |
| CVE-2025-53394 | HIGH | 7.7 | 0.1% | Aug 4, 2025 | Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges vi... |
| CVE-2025-38741 | HIGH | 7.5 | 0.4% | Aug 4, 2025 | Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote at... |
| CVE-2025-8518 | HIGH | 7.2 | 1.3% | Aug 4, 2025 | A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function S... |
| CVE-2025-51534 | HIGH | 8.1 | 0.4% | Aug 4, 2025 | A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers ... |
| CVE-2025-44963 | HIGH | 8.1 | 0.6% | Aug 4, 2025 | RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded ... |
| CVE-2025-44961 | HIGH | 8.8 | 2.1% | Aug 4, 2025 | In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided b... |
| CVE-2025-44960 | HIGH | 8.8 | 1.8% | Aug 4, 2025 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route. |
| CVE-2025-44958 | HIGH | 7.5 | 0.3% | Aug 4, 2025 | RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format. |
| CVE-2025-44957 | HIGH | 8.8 | 0.8% | Aug 4, 2025 | Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP hea... |
| CVE-2025-44955 | HIGH | 8.8 | 0.4% | Aug 4, 2025 | RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password. |
| CVE-2025-44643 | HIGH | 8.6 | 0.2% | Aug 4, 2025 | Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R... |
| CVE-2025-30099 | HIGH | 7.8 | 0.4% | Aug 4, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now