2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50467 | MEDIUM | 6.5 | 0.2% | Aug 8, 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l... |
| CVE-2025-50466 | MEDIUM | 6.5 | 0.3% | Aug 8, 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l... |
| CVE-2025-47872 | MEDIUM | 6.9 | 0.3% | Aug 8, 2025 | The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and u... |
| CVE-2025-4576 | MEDIUM | 6.1 | 0.5% | Aug 8, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025... |
| CVE-2025-36023 | MEDIUM | 6.5 | 0.2% | Aug 8, 2025 | IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authent... |
| CVE-2025-8749 | MEDIUM | 6.5 | 0.4% | Aug 8, 2025 | Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR R... |
| CVE-2025-6572 | MEDIUM | 5.9 | 0.2% | Aug 8, 2025 | The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does... |
| CVE-2025-54959 | MEDIUM | 5.3 | 0.3% | Aug 8, 2025 | Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is explo... |
| CVE-2025-54958 | MEDIUM | 6.3 | 0.8% | Aug 8, 2025 | Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is e... |
| CVE-2025-54940 | MEDIUM | 4.6 | 0.2% | Aug 8, 2025 | An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerabilit... |
| CVE-2025-8707 | MEDIUM | 5.5 | 0.2% | Aug 8, 2025 | A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unkn... |
| CVE-2025-54793 | MEDIUM | 6.1 | 0.6% | Aug 8, 2025 | Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulner... |
| CVE-2025-54368 | MEDIUM | 6.8 | 0.2% | Aug 8, 2025 | uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were hand... |
| CVE-2025-47808 | MEDIUM | 5.6 | 0.4% | Aug 7, 2025 | In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while par... |
| CVE-2025-47807 | MEDIUM | 5.5 | 0.2% | Aug 7, 2025 | In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer wh... |
| CVE-2025-47806 | MEDIUM | 5.6 | 0.3% | Aug 7, 2025 | In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack ... |
| CVE-2025-47183 | MEDIUM | 6.6 | 0.2% | Aug 7, 2025 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer whil... |
| CVE-2025-8697 | MEDIUM | 6.3 | 2.2% | Aug 7, 2025 | A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function Stdi... |
| CVE-2025-7195 | MEDIUM | 6.4 | 0.2% | Aug 7, 2025 | Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used... |
| CVE-2025-51533 | MEDIUM | 5.3 | 0.3% | Aug 7, 2025 | An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access in... |
| CVE-2025-54397 | MEDIUM | 4.3 | 0.2% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Se... |
| CVE-2025-54396 | MEDIUM | 5.4 | 0.2% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated u... |
| CVE-2025-54395 | MEDIUM | 6.1 | 0.2% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configu... |
| CVE-2025-54394 | MEDIUM | 5.3 | 0.3% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credenti... |
| CVE-2025-54393 | MEDIUM | 5.4 | 0.2% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authent... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now