2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26065 | HIGH | 7.3 | 0.3% | Aug 4, 2025 | A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb... |
| CVE-2025-8109 | HIGH | 8.8 | 0.4% | Aug 4, 2025 | Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read o... |
| CVE-2025-36607 | HIGH | 7.8 | 0.5% | Aug 4, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authen... |
| CVE-2025-36606 | HIGH | 7.8 | 0.5% | Aug 4, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An... |
| CVE-2025-6204 | HIGH | 8 | 75.3% | Aug 4, 2025 | An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 throu... |
| CVE-2025-41691 | HIGH | 7.5 | 0.5% | Aug 4, 2025 | An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime system... |
| CVE-2025-41659 | HIGH | 8.3 | 0.2% | Aug 4, 2025 | A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and wri... |
| CVE-2025-20702 | HIGH | 8.8 | 5.2% | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remo... |
| CVE-2025-20701 | HIGH | 8.8 | 6.2% | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This cou... |
| CVE-2025-20700 | HIGH | 8.8 | 6.2% | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protoc... |
| CVE-2025-8500 | HIGH | 8.8 | 0.5% | Aug 3, 2025 | A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This iss... |
| CVE-2025-54955 | HIGH | 8.1 | 0.3% | Aug 3, 2025 | OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race c... |
| CVE-2025-23284 | HIGH | 7.8 | 0.2% | Aug 2, 2025 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack bu... |
| CVE-2025-23283 | HIGH | 7.8 | 0.2% | Aug 2, 2025 | NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious ... |
| CVE-2025-23281 | HIGH | 7 | 0.2% | Aug 2, 2025 | NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can... |
| CVE-2025-23279 | HIGH | 7 | 0.1% | Aug 2, 2025 | NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to esc... |
| CVE-2025-23278 | HIGH | 7.1 | 0.2% | Aug 2, 2025 | NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index val... |
| CVE-2025-23277 | HIGH | 7.3 | 0.2% | Aug 2, 2025 | NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could ... |
| CVE-2025-23276 | HIGH | 7.8 | 0.2% | Aug 2, 2025 | NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful... |
| CVE-2025-6754 | HIGH | 8.8 | 0.4% | Aug 2, 2025 | The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both t... |
| CVE-2025-7694 | HIGH | 7.5 | 0.8% | Aug 2, 2025 | The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ... |
| CVE-2025-6076 | HIGH | 8.8 | 0.7% | Aug 2, 2025 | Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "repor... |
| CVE-2025-54796 | HIGH | 7.5 | 0.4% | Aug 2, 2025 | Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows... |
| CVE-2025-54782 | HIGH | 8.8 | 46.2% | Aug 2, 2025 | Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remo... |
| CVE-2025-54136 | HIGH | 8.8 | 7.5% | Aug 2, 2025 | Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now