2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9602 | MEDIUM | 6.5 | 0.2% | Aug 29, 2025 | A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. P... |
| CVE-2025-54142 | MEDIUM | 4 | 0.2% | Aug 29, 2025 | Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because the... |
| CVE-2025-43284 | MEDIUM | 5.5 | 0.1% | Aug 29, 2025 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sono... |
| CVE-2025-9595 | MEDIUM | 6.1 | 0.4% | Aug 29, 2025 | A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown... |
| CVE-2025-58061 | MEDIUM | 5.5 | 0.1% | Aug 28, 2025 | OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernete... |
| CVE-2025-58058 | MEDIUM | 5.3 | 0.4% | Aug 28, 2025 | xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put ... |
| CVE-2025-57220 | MEDIUM | 5.3 | 1.0% | Aug 28, 2025 | An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privilege... |
| CVE-2025-57219 | MEDIUM | 5.3 | 0.2% | Aug 28, 2025 | Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attacke... |
| CVE-2025-9195 | MEDIUM | 4.4 | 0.1% | Aug 28, 2025 | Improper input validation in firmware of some Solidigm DC Products may allow an attacker with local access to cause a De... |
| CVE-2025-57218 | MEDIUM | 5.3 | 0.5% | Aug 28, 2025 | Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g paramet... |
| CVE-2025-57217 | MEDIUM | 5.3 | 0.5% | Aug 28, 2025 | Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter ... |
| CVE-2025-31971 | MEDIUM | 5.1 | 0.1% | Aug 28, 2025 | AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability. The issue may allow attackers to launch a se... |
| CVE-2025-57759 | MEDIUM | 4.3 | 0.2% | Aug 28, 2025 | Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, b... |
| CVE-2025-57758 | MEDIUM | 4.3 | 0.2% | Aug 28, 2025 | Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in t... |
| CVE-2025-57757 | MEDIUM | 5.3 | 0.3% | Aug 28, 2025 | Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains pro... |
| CVE-2025-57756 | MEDIUM | 5.3 | 0.3% | Aug 28, 2025 | Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected conten... |
| CVE-2025-31979 | MEDIUM | 5.4 | 0.2% | Aug 28, 2025 | A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to p... |
| CVE-2025-31977 | MEDIUM | 6.5 | 0.1% | Aug 28, 2025 | HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms. An attacker with net... |
| CVE-2025-31972 | MEDIUM | 6.5 | 0.1% | Aug 28, 2025 | HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS en... |
| CVE-2025-29364 | MEDIUM | 6.5 | 0.4% | Aug 28, 2025 | spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in the READ_SYSCALL and WRITE_SYSCALL system call... |
| CVE-2025-25010 | MEDIUM | 6.5 | 0.3% | Aug 28, 2025 | Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectl... |
| CVE-2025-56236 | MEDIUM | 6.1 | 0.2% | Aug 28, 2025 | FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated us... |
| CVE-2025-54995 | MEDIUM | 6.5 | 0.4% | Aug 28, 2025 | Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP... |
| CVE-2025-52054 | MEDIUM | 5.3 | 0.3% | Aug 28, 2025 | An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The roo... |
| CVE-2025-51972 | MEDIUM | 6.5 | 0.2% | Aug 28, 2025 | A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to impro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now