2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44957 | HIGH | 8.8 | 0.8% | Aug 4, 2025 | Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP hea... |
| CVE-2025-44955 | HIGH | 8.8 | 0.4% | Aug 4, 2025 | RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password. |
| CVE-2025-44643 | HIGH | 8.6 | 0.2% | Aug 4, 2025 | Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R... |
| CVE-2025-30099 | HIGH | 7.8 | 0.4% | Aug 4, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-26065 | HIGH | 7.3 | 0.3% | Aug 4, 2025 | A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb... |
| CVE-2025-8109 | HIGH | 8.8 | 0.4% | Aug 4, 2025 | Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read o... |
| CVE-2025-36607 | HIGH | 7.8 | 0.5% | Aug 4, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authen... |
| CVE-2025-36606 | HIGH | 7.8 | 0.5% | Aug 4, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An... |
| CVE-2025-6204 | HIGH | 8 | 75.3% | Aug 4, 2025 | An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 throu... |
| CVE-2025-41691 | HIGH | 7.5 | 0.5% | Aug 4, 2025 | An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime system... |
| CVE-2025-41659 | HIGH | 8.3 | 0.2% | Aug 4, 2025 | A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and wri... |
| CVE-2025-20702 | HIGH | 8.8 | 5.2% | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remo... |
| CVE-2025-20701 | HIGH | 8.8 | 7.7% | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This cou... |
| CVE-2025-20700 | HIGH | 8.8 | 6.2% | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protoc... |
| CVE-2025-8500 | HIGH | 8.8 | 0.5% | Aug 3, 2025 | A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This iss... |
| CVE-2025-54955 | HIGH | 8.1 | 0.3% | Aug 3, 2025 | OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race c... |
| CVE-2025-23284 | HIGH | 7.8 | 0.2% | Aug 2, 2025 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack bu... |
| CVE-2025-23283 | HIGH | 7.8 | 0.2% | Aug 2, 2025 | NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious ... |
| CVE-2025-23281 | HIGH | 7 | 0.2% | Aug 2, 2025 | NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can... |
| CVE-2025-23279 | HIGH | 7 | 0.1% | Aug 2, 2025 | NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to esc... |
| CVE-2025-23278 | HIGH | 7.1 | 0.2% | Aug 2, 2025 | NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index val... |
| CVE-2025-23277 | HIGH | 7.3 | 0.2% | Aug 2, 2025 | NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could ... |
| CVE-2025-23276 | HIGH | 7.8 | 0.2% | Aug 2, 2025 | NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful... |
| CVE-2025-6754 | HIGH | 8.8 | 0.4% | Aug 2, 2025 | The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both t... |
| CVE-2025-7694 | HIGH | 7.5 | 0.8% | Aug 2, 2025 | The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now