2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2183 | MEDIUM | 5.3 | 0.1% | Aug 13, 2025 | An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect t... |
| CVE-2025-2182 | MEDIUM | 5.6 | 0.1% | Aug 13, 2025 | A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure... |
| CVE-2025-2181 | MEDIUM | 5.9 | 0.1% | Aug 13, 2025 | A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleart... |
| CVE-2025-2180 | MEDIUM | 4.8 | 0.2% | Aug 13, 2025 | An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to e... |
| CVE-2025-8918 | MEDIUM | 4.8 | 0.3% | Aug 13, 2025 | A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /int... |
| CVE-2025-54500 | MEDIUM | 5.3 | 0.5% | Aug 13, 2025 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to bre... |
| CVE-2025-53859 | MEDIUM | 6.3 | 0.4% | Aug 13, 2025 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated at... |
| CVE-2025-51691 | MEDIUM | 6.1 | 0.4% | Aug 13, 2025 | Cross-Site Scripting (XSS) vulnerability found in MarkTwo commit e3a1d3f90cce4ea9c26efcbbf3a1cbfb9dcdb298 (May 2025) all... |
| CVE-2025-50690 | MEDIUM | 6.1 | 0.2% | Aug 13, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in SpatialReference.org (OSGeo/spatialreference.org) versions prior to... |
| CVE-2025-55668 | MEDIUM | 6.5 | 0.8% | Aug 13, 2025 | Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 thr... |
| CVE-2025-55160 | MEDIUM | 5.3 | 0.4% | Aug 13, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2025-55005 | MEDIUM | 5.5 | 0.2% | Aug 13, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1,... |
| CVE-2025-55004 | MEDIUM | 4.3 | 0.5% | Aug 13, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1,... |
| CVE-2025-54791 | MEDIUM | 5.3 | 0.2% | Aug 13, 2025 | OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when rese... |
| CVE-2025-52392 | MEDIUM | 5.4 | 0.8% | Aug 13, 2025 | Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout m... |
| CVE-2025-52386 | MEDIUM | 5.4 | 0.2% | Aug 13, 2025 | CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file |
| CVE-2025-55280 | MEDIUM | 5.2 | 0.1% | Aug 13, 2025 | This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plai... |
| CVE-2025-55279 | MEDIUM | 6.9 | 0.2% | Aug 13, 2025 | This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. A... |
| CVE-2025-54465 | MEDIUM | 6.8 | 0.2% | Aug 13, 2025 | This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the... |
| CVE-2025-8916 | MEDIUM | 6.3 | 0.4% | Aug 13, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on... |
| CVE-2025-8911 | MEDIUM | 6.1 | 0.3% | Aug 13, 2025 | Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthen... |
| CVE-2025-8910 | MEDIUM | 6.1 | 0.3% | Aug 13, 2025 | Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthen... |
| CVE-2025-8762 | MEDIUM | 6.8 | 0.2% | Aug 13, 2025 | A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the comp... |
| CVE-2025-8891 | MEDIUM | 4.3 | 0.2% | Aug 13, 2025 | The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to m... |
| CVE-2025-8491 | MEDIUM | 4.3 | 0.2% | Aug 13, 2025 | The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now