2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54478 | MEDIUM | 5.3 | 0.2% | Aug 11, 2025 | Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which... |
| CVE-2025-54458 | MEDIUM | 5 | 0.2% | Aug 11, 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows a... |
| CVE-2025-53910 | MEDIUM | 4 | 0.2% | Aug 11, 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ... |
| CVE-2025-53514 | MEDIUM | 5.9 | 0.3% | Aug 11, 2025 | Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ... |
| CVE-2025-51824 | MEDIUM | 6.5 | 0.2% | Aug 11, 2025 | libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c. |
| CVE-2025-51823 | MEDIUM | 6.5 | 0.2% | Aug 11, 2025 | libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parame... |
| CVE-2025-48731 | MEDIUM | 6.4 | 0.2% | Aug 11, 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows a... |
| CVE-2025-44001 | MEDIUM | 4 | 0.2% | Aug 11, 2025 | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ... |
| CVE-2025-25229 | MEDIUM | 5.4 | 0.2% | Aug 11, 2025 | Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privi... |
| CVE-2025-8866 | MEDIUM | 5.1 | 0.3% | Aug 11, 2025 | YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An un... |
| CVE-2025-38499 | MEDIUM | 5.5 | 0.1% | Aug 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_... |
| CVE-2025-8865 | MEDIUM | 4.1 | 0.1% | Aug 11, 2025 | The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when... |
| CVE-2025-8864 | MEDIUM | 6.8 | 0.2% | Aug 11, 2025 | Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup lo... |
| CVE-2025-8852 | MEDIUM | 4.3 | 0.4% | Aug 11, 2025 | A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/u... |
| CVE-2025-8851 | MEDIUM | 5.3 | 0.2% | Aug 11, 2025 | A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffe... |
| CVE-2025-8847 | MEDIUM | 5.4 | 0.3% | Aug 11, 2025 | A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the... |
| CVE-2025-8844 | MEDIUM | 5.5 | 0.2% | Aug 11, 2025 | A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_te... |
| CVE-2025-8841 | MEDIUM | 6.1 | 0.3% | Aug 11, 2025 | A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the func... |
| CVE-2025-8840 | MEDIUM | 5.4 | 0.4% | Aug 11, 2025 | A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/delete... |
| CVE-2025-8661 | MEDIUM | 6.1 | 0.2% | Aug 11, 2025 | A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data e... |
| CVE-2025-8835 | MEDIUM | 5.5 | 0.2% | Aug 11, 2025 | A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of th... |
| CVE-2025-7965 | MEDIUM | 4.3 | 0.1% | Aug 11, 2025 | The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, ... |
| CVE-2025-27562 | MEDIUM | 5.5 | 0.1% | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. |
| CVE-2025-27536 | MEDIUM | 5.5 | 0.1% | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion. |
| CVE-2025-26690 | MEDIUM | 5.5 | 0.1% | Aug 11, 2025 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now