2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20025 | MEDIUM | 4.4 | 0.1% | Aug 12, 2025 | Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticate... |
| CVE-2025-20023 | MEDIUM | 6.7 | 0.1% | Aug 12, 2025 | Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to p... |
| CVE-2025-20017 | MEDIUM | 6.7 | 0.1% | Aug 12, 2025 | Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated u... |
| CVE-2025-8452 | MEDIUM | 4.3 | 0.2% | Aug 12, 2025 | By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-fu... |
| CVE-2025-55011 | MEDIUM | 5.3 | 0.3% | Aug 12, 2025 | Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskF... |
| CVE-2025-54800 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can intro... |
| CVE-2025-3089 | MEDIUM | 5.3 | 0.4% | Aug 12, 2025 | ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This v... |
| CVE-2025-5468 | MEDIUM | 5.5 | 0.3% | Aug 12, 2025 | Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure bef... |
| CVE-2025-5466 | MEDIUM | 4.9 | 0.6% | Aug 12, 2025 | XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before ... |
| CVE-2025-22834 | MEDIUM | 5.3 | 0.1% | Aug 12, 2025 | AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Success... |
| CVE-2025-22830 | MEDIUM | 6.7 | 0.1% | Aug 12, 2025 | APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A successful ex... |
| CVE-2025-43735 | MEDIUM | 6.1 | 0.2% | Aug 12, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024... |
| CVE-2025-40766 | MEDIUM | 6.8 | 0.2% | Aug 12, 2025 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected a... |
| CVE-2025-40753 | MEDIUM | 6.8 | 0.1% | Aug 12, 2025 | A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWE... |
| CVE-2025-40752 | MEDIUM | 6.8 | 0.1% | Aug 12, 2025 | A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWE... |
| CVE-2025-40584 | MEDIUM | 6.8 | 0.2% | Aug 12, 2025 | A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), S... |
| CVE-2025-33023 | MEDIUM | 5.1 | 0.3% | Aug 12, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGE... |
| CVE-2025-30034 | MEDIUM | 5.5 | 0.1% | Aug 12, 2025 | A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected devices do not prop... |
| CVE-2025-43736 | MEDIUM | 4.3 | 0.3% | Aug 12, 2025 | A Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP... |
| CVE-2025-8885 | MEDIUM | 6.3 | 0.5% | Aug 12, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on... |
| CVE-2025-26398 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnera... |
| CVE-2025-8874 | MEDIUM | 6.4 | 0.2% | Aug 12, 2025 | The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ... |
| CVE-2025-8767 | MEDIUM | 4.8 | 0.3% | Aug 12, 2025 | The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16... |
| CVE-2025-8482 | MEDIUM | 4.3 | 0.2% | Aug 12, 2025 | The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This ... |
| CVE-2025-47444 | MEDIUM | 5.3 | 0.2% | Aug 12, 2025 | Missing Authorization vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Exploiting Incorrectly ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now