2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5942 | MEDIUM | 5.7 | 0.1% | Aug 14, 2025 | Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully ex... |
| CVE-2025-0309 | MEDIUM | 6 | 0.2% | Aug 14, 2025 | An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges... |
| CVE-2025-8934 | MEDIUM | 6.1 | 0.4% | Aug 14, 2025 | A vulnerability has been found in 1000 Projects Sales Management System 1.0. Affected is an unknown function of the file... |
| CVE-2025-8933 | MEDIUM | 6.1 | 0.4% | Aug 14, 2025 | A vulnerability was identified in 1000 Projects Sales Management System 1.0. This issue affects some unknown processing ... |
| CVE-2025-55199 | MEDIUM | 6.5 | 0.3% | Aug 14, 2025 | Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file... |
| CVE-2025-55198 | MEDIUM | 6.5 | 0.3% | Aug 14, 2025 | Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml fil... |
| CVE-2025-55194 | MEDIUM | 5.7 | 0.3% | Aug 13, 2025 | Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authentica... |
| CVE-2025-45313 | MEDIUM | 6.1 | 0.2% | Aug 13, 2025 | A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbi... |
| CVE-2025-43989 | MEDIUM | 6.5 | 5.8% | Aug 13, 2025 | The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandl... |
| CVE-2025-8920 | MEDIUM | 5.4 | 0.3% | Aug 13, 2025 | A vulnerability was identified in Portabilis i-Diario 1.6. Affected by this vulnerability is an unknown functionality of... |
| CVE-2025-8919 | MEDIUM | 4.8 | 0.3% | Aug 13, 2025 | A vulnerability was determined in Portabilis i-Diario up to 1.6. Affected is an unknown function of the file /objetivos-... |
| CVE-2025-8770 | MEDIUM | 6.5 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18... |
| CVE-2025-7739 | MEDIUM | 5.4 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditio... |
| CVE-2025-7734 | MEDIUM | 5.4 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2... |
| CVE-2025-6186 | MEDIUM | 5.4 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that... |
| CVE-2025-5819 | MEDIUM | 5 | 0.2% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.... |
| CVE-2025-50946 | MEDIUM | 6.5 | 1.3% | Aug 13, 2025 | OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/a... |
| CVE-2025-45317 | MEDIUM | 6.5 | 0.3% | Aug 13, 2025 | A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute ar... |
| CVE-2025-45316 | MEDIUM | 6.1 | 0.3% | Aug 13, 2025 | A cross-site scripting (XSS) vulnerability in the TextBlockModule.php component of hortusfox-web v4.4 allows attackers t... |
| CVE-2025-45315 | MEDIUM | 5.4 | 0.2% | Aug 13, 2025 | A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers ... |
| CVE-2025-45314 | MEDIUM | 6.1 | 0.3% | Aug 13, 2025 | A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute a... |
| CVE-2025-2937 | MEDIUM | 6.5 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.... |
| CVE-2025-2614 | MEDIUM | 6.5 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.... |
| CVE-2025-2498 | MEDIUM | 4.3 | 0.2% | Aug 13, 2025 | An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2... |
| CVE-2025-2184 | MEDIUM | 5.3 | 0.2% | Aug 13, 2025 | A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share iden... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now