2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0082 | MEDIUM | 5.5 | 0.1% | Aug 26, 2025 | In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across us... |
| CVE-2025-50975 | MEDIUM | 5.4 | 0.3% | Aug 26, 2025 | IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT... |
| CVE-2025-57818 | MEDIUM | 6.3 | 0.3% | Aug 26, 2025 | Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to version 2.0.1, a server-side reques... |
| CVE-2025-50976 | MEDIUM | 6.1 | 0.2% | Aug 26, 2025 | IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK,... |
| CVE-2025-57425 | MEDIUM | 6.1 | 0.3% | Aug 26, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability in SourceCodester FAQ Management System 1.0 allows an authenticated at... |
| CVE-2025-52184 | MEDIUM | 6.1 | 0.3% | Aug 26, 2025 | Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic... |
| CVE-2025-50974 | MEDIUM | 6.5 | 0.4% | Aug 26, 2025 | The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied... |
| CVE-2025-1494 | MEDIUM | 6.1 | 0.3% | Aug 26, 2025 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim.... |
| CVE-2025-57813 | MEDIUM | 5.9 | 0.4% | Aug 26, 2025 | traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists wh... |
| CVE-2025-56432 | MEDIUM | 6.1 | 0.7% | Aug 26, 2025 | A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to exec... |
| CVE-2025-52219 | MEDIUM | 6.5 | 0.2% | Aug 26, 2025 | SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fie... |
| CVE-2025-52217 | MEDIUM | 5.4 | 0.2% | Aug 26, 2025 | SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly hand... |
| CVE-2025-52037 | MEDIUM | 6.1 | 0.2% | Aug 26, 2025 | A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.p... |
| CVE-2025-52036 | MEDIUM | 6.1 | 0.2% | Aug 26, 2025 | A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.p... |
| CVE-2025-52035 | MEDIUM | 6.1 | 0.2% | Aug 26, 2025 | A vulnerability in NotesCMS and specifically in the page /index.php?route=notes. The manipulation of the title of the se... |
| CVE-2025-25737 | MEDIUM | 6.8 | 0.4% | Aug 26, 2025 | Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were disco... |
| CVE-2025-25736 | MEDIUM | 6.8 | 0.3% | Aug 26, 2025 | Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android ... |
| CVE-2025-25735 | MEDIUM | 4.6 | 0.2% | Aug 26, 2025 | Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were disco... |
| CVE-2025-25734 | MEDIUM | 6.8 | 0.3% | Aug 26, 2025 | Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discov... |
| CVE-2025-25732 | MEDIUM | 6.8 | 0.3% | Aug 26, 2025 | Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.8... |
| CVE-2025-9190 | MEDIUM | 4.8 | 0.1% | Aug 26, 2025 | The configuration of Cursor on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileg... |
| CVE-2025-8700 | MEDIUM | 4.8 | 0.1% | Aug 26, 2025 | Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", al... |
| CVE-2025-8597 | MEDIUM | 4.8 | 0.1% | Aug 26, 2025 | MacVim's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows lo... |
| CVE-2025-53813 | MEDIUM | 4.8 | 0.1% | Aug 26, 2025 | The configuration of Nozbe on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivilege... |
| CVE-2025-53811 | MEDIUM | 4.8 | 0.1% | Aug 26, 2025 | The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivil... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now