2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62307 | MEDIUM | 5.4 | — | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, ... |
| CVE-2025-53999 | MEDIUM | 6.5 | — | Aug 20, 2026 | Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. |
| CVE-2025-14602 | MEDIUM | 5.3 | — | Aug 20, 2026 | The application generates uploaded file names using a weak and predictable method based on the request timestamp. This a... |
| CVE-2025-36398 | MEDIUM | 5.4 | — | Aug 19, 2026 | IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authe... |
| CVE-2025-11729 | MEDIUM | 4.3 | — | Aug 19, 2026 | The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized acc... |
| CVE-2025-9211 | MEDIUM | 6.7 | — | Aug 18, 2026 | Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 al... |
| CVE-2025-10005 | MEDIUM | 4.3 | — | Aug 16, 2026 | The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure ... |
| CVE-2025-71405 | MEDIUM | 5.1 | — | Aug 14, 2026 | chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses t... |
| CVE-2025-10308 | MEDIUM | 4.3 | — | Aug 14, 2026 | The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-62314 | MEDIUM | 5.6 | — | Aug 13, 2026 | HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or s... |
| CVE-2025-52640 | MEDIUM | 4.7 | — | Aug 13, 2026 | HCL AION is affected by a vulnerability where the shared storage used by product components is architected without suffi... |
| CVE-2025-59320 | MEDIUM | 4.6 | — | Aug 12, 2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk s... |
| CVE-2025-41771 | MEDIUM | 4.3 | — | Aug 12, 2026 | An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl... |
| CVE-2025-15687 | MEDIUM | 4.3 | — | Aug 12, 2026 | A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF ... |
| CVE-2025-15686 | MEDIUM | 4.3 | — | Aug 12, 2026 | A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the com... |
| CVE-2025-15685 | MEDIUM | 6.3 | — | Aug 12, 2026 | A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the componen... |
| CVE-2025-15684 | MEDIUM | 5.3 | — | Aug 12, 2026 | A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/com... |
| CVE-2025-48506 | MEDIUM | 4.6 | — | Aug 11, 2026 | Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into t... |
| CVE-2025-35987 | MEDIUM | 4.3 | — | Aug 11, 2026 | Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives... |
| CVE-2025-35973 | MEDIUM | 4.5 | — | Aug 11, 2026 | Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow a... |
| CVE-2025-31938 | MEDIUM | 4.3 | — | Aug 11, 2026 | Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(... |
| CVE-2025-31936 | MEDIUM | 5.7 | — | Aug 11, 2026 | Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) ... |
| CVE-2025-31356 | MEDIUM | 5.7 | — | Aug 11, 2026 | Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: H... |
| CVE-2025-0041 | MEDIUM | 4.6 | — | Aug 11, 2026 | Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a... |
| CVE-2025-30240 | MEDIUM | 5.1 | — | Aug 10, 2026 | The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now