2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51053 | MEDIUM | 6.1 | 0.4% | Aug 6, 2025 | A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject... |
| CVE-2025-51052 | MEDIUM | 6.5 | 0.4% | Aug 6, 2025 | A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem ... |
| CVE-2025-50740 | MEDIUM | 6.1 | 0.2% | Aug 6, 2025 | AutoConnect 1.4.2, an Arduino library, is vulnerable to a cross site scripting (xss) vulnerability. The AutoConnect web ... |
| CVE-2025-46660 | MEDIUM | 5.3 | 0.3% | Aug 6, 2025 | An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt. |
| CVE-2025-8667 | MEDIUM | 6.3 | 2.2% | Aug 6, 2025 | A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75b... |
| CVE-2025-8665 | MEDIUM | 6.3 | 2.2% | Aug 6, 2025 | A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the f... |
| CVE-2025-8419 | MEDIUM | 5.3 | 0.4% | Aug 6, 2025 | A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Inje... |
| CVE-2025-20332 | MEDIUM | 4.3 | 0.4% | Aug 6, 2025 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modi... |
| CVE-2025-20331 | MEDIUM | 5.4 | 0.2% | Aug 6, 2025 | A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot... |
| CVE-2025-20215 | MEDIUM | 5.4 | 0.1% | Aug 6, 2025 | A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network... |
| CVE-2025-51531 | MEDIUM | 6.1 | 0.2% | Aug 6, 2025 | A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arb... |
| CVE-2025-48394 | MEDIUM | 4.7 | 0.3% | Aug 6, 2025 | An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the... |
| CVE-2025-48393 | MEDIUM | 5.7 | 0.2% | Aug 6, 2025 | The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potential... |
| CVE-2025-51308 | MEDIUM | 5.3 | 0.3% | Aug 6, 2025 | In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a R... |
| CVE-2025-51306 | MEDIUM | 6.5 | 0.3% | Aug 6, 2025 | In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the ap... |
| CVE-2025-50234 | MEDIUM | 6.5 | 0.2% | Aug 6, 2025 | MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where ... |
| CVE-2025-50233 | MEDIUM | 6.5 | 0.4% | Aug 6, 2025 | A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insuffic... |
| CVE-2025-2028 | MEDIUM | 5.3 | 0.2% | Aug 6, 2025 | Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying coun... |
| CVE-2025-8616 | MEDIUM | 6.1 | 0.4% | Aug 6, 2025 | A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the use... |
| CVE-2025-5197 | MEDIUM | 5.3 | 0.4% | Aug 6, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifical... |
| CVE-2025-46391 | MEDIUM | 6.5 | 0.2% | Aug 6, 2025 | CWE-284: Improper Access Control |
| CVE-2025-46389 | MEDIUM | 6.5 | 0.2% | Aug 6, 2025 | CWE-620: Unverified Password Change |
| CVE-2025-46388 | MEDIUM | 4.3 | 0.2% | Aug 6, 2025 | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2025-8620 | MEDIUM | 5.3 | 0.5% | Aug 6, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all ... |
| CVE-2025-7202 | MEDIUM | 5.1 | 0.2% | Aug 6, 2025 | A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now