2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50592 | MEDIUM | 5.4 | 0.2% | Aug 5, 2025 | Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player. |
| CVE-2025-45512 | MEDIUM | 6.5 | 0.3% | Aug 5, 2025 | A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attack... |
| CVE-2025-51857 | MEDIUM | 6.1 | 0.3% | Aug 5, 2025 | The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS a... |
| CVE-2025-51627 | MEDIUM | 6.5 | 0.2% | Aug 5, 2025 | Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-le... |
| CVE-2025-51060 | MEDIUM | 6.5 | 0.3% | Aug 5, 2025 | An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0... |
| CVE-2025-50688 | MEDIUM | 6.5 | 4.8% | Aug 5, 2025 | A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file u... |
| CVE-2025-50454 | MEDIUM | 6.5 | 0.3% | Aug 5, 2025 | An Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an unauthorized attacker to log ... |
| CVE-2025-8585 | MEDIUM | 5.3 | 0.2% | Aug 5, 2025 | A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the fun... |
| CVE-2025-43980 | MEDIUM | 6.5 | 0.2% | Aug 5, 2025 | An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN. They enable the SSH service by default with the ... |
| CVE-2025-47152 | MEDIUM | 6.5 | 0.5% | Aug 5, 2025 | An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396... |
| CVE-2025-46958 | MEDIUM | 5.4 | 0.3% | Aug 5, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-27931 | MEDIUM | 6.5 | 0.5% | Aug 5, 2025 | An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using ... |
| CVE-2025-8555 | MEDIUM | 5.4 | 0.3% | Aug 5, 2025 | A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown funct... |
| CVE-2025-8554 | MEDIUM | 5.4 | 0.2% | Aug 5, 2025 | A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some... |
| CVE-2025-8553 | MEDIUM | 5.4 | 0.2% | Aug 5, 2025 | A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code ... |
| CVE-2025-8552 | MEDIUM | 5.4 | 0.2% | Aug 5, 2025 | A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the... |
| CVE-2025-8551 | MEDIUM | 5.4 | 0.2% | Aug 5, 2025 | A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some u... |
| CVE-2025-8295 | MEDIUM | 6.4 | 0.2% | Aug 5, 2025 | The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ paramete... |
| CVE-2025-8294 | MEDIUM | 6.4 | 0.2% | Aug 5, 2025 | The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all v... |
| CVE-2025-2810 | MEDIUM | 5.5 | 0.1% | Aug 5, 2025 | A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key. |
| CVE-2025-8550 | MEDIUM | 5.4 | 0.6% | Aug 5, 2025 | A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerabilit... |
| CVE-2025-8315 | MEDIUM | 6.4 | 0.2% | Aug 5, 2025 | The WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter i... |
| CVE-2025-8313 | MEDIUM | 6.4 | 0.2% | Aug 5, 2025 | The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter ... |
| CVE-2025-8547 | MEDIUM | 5.5 | 0.4% | Aug 5, 2025 | A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown... |
| CVE-2025-8546 | MEDIUM | 5.5 | 0.4% | Aug 5, 2025 | A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function ad... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now