2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20238 | MEDIUM | 6 | 0.1% | Aug 14, 2025 | A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Def... |
| CVE-2025-20237 | MEDIUM | 6 | 0.1% | Aug 14, 2025 | A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Def... |
| CVE-2025-20235 | MEDIUM | 6.1 | 0.3% | Aug 14, 2025 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al... |
| CVE-2025-20225 | MEDIUM | 5.8 | 0.6% | Aug 14, 2025 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Fi... |
| CVE-2025-20224 | MEDIUM | 5.8 | 0.6% | Aug 14, 2025 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Applian... |
| CVE-2025-20220 | MEDIUM | 6 | 0.2% | Aug 14, 2025 | A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat De... |
| CVE-2025-20219 | MEDIUM | 5.3 | 0.4% | Aug 14, 2025 | A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive ... |
| CVE-2025-20218 | MEDIUM | 4.9 | 0.4% | Aug 14, 2025 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al... |
| CVE-2025-20135 | MEDIUM | 4.3 | 0.2% | Aug 14, 2025 | A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and... |
| CVE-2025-54409 | MEDIUM | 5.5 | 0.2% | Aug 14, 2025 | AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference v... |
| CVE-2025-54389 | MEDIUM | 5.5 | 0.2% | Aug 14, 2025 | AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization... |
| CVE-2025-53631 | MEDIUM | 5.4 | 0.2% | Aug 14, 2025 | flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitt... |
| CVE-2025-38745 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log Fi... |
| CVE-2025-27847 | MEDIUM | 4.3 | 0.2% | Aug 14, 2025 | In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout. |
| CVE-2025-27846 | MEDIUM | 4.3 | 0.2% | Aug 14, 2025 | In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges beca... |
| CVE-2025-26484 | MEDIUM | 4.9 | 0.3% | Aug 14, 2025 | Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerabil... |
| CVE-2025-55675 | MEDIUM | 6.5 | 0.5% | Aug 14, 2025 | Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization chec... |
| CVE-2025-55674 | MEDIUM | 6.5 | 0.6% | Aug 14, 2025 | A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL fun... |
| CVE-2025-55673 | MEDIUM | 4.3 | 0.5% | Aug 14, 2025 | When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query f... |
| CVE-2025-55672 | MEDIUM | 5.4 | 0.6% | Aug 14, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user... |
| CVE-2025-36581 | MEDIUM | 5.5 | 0.1% | Aug 14, 2025 | Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and prior, contain(s) an Access of Memory Location After End of ... |
| CVE-2025-54706 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical ... |
| CVE-2025-54705 | MEDIUM | 4.3 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured... |
| CVE-2025-54704 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy El... |
| CVE-2025-54703 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Cros... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now