2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-70340 | MEDIUM | 6.5 | 0.2% | Aug 26, 2026 | A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms ... |
| CVE-2025-70293 | CRITICAL | 9.8 | 0.5% | Aug 26, 2026 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_b... |
| CVE-2025-70290 | CRITICAL | 9.8 | 0.5% | Aug 26, 2026 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support c... |
| CVE-2025-61165 | CRITICAL | 9.8 | 0.4% | Aug 26, 2026 | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac... |
| CVE-2025-61164 | HIGH | 7.5 | 0.3% | Aug 26, 2026 | Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. |
| CVE-2025-61163 | CRITICAL | 9.8 | 0.3% | Aug 26, 2026 | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This... |
| CVE-2025-61162 | HIGH | 7.5 | 0.2% | Aug 26, 2026 | Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req... |
| CVE-2025-56798 | HIGH | 8.8 | 0.2% | Aug 26, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows ... |
| CVE-2025-29419 | HIGH | 7.1 | 0.2% | Aug 26, 2026 | CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack. |
| CVE-2025-10903 | MEDIUM | 6.5 | 0.4% | Aug 26, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.... |
| CVE-2025-71407 | — | — | 0.4% | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2025-71406 | — | — | 0.2% | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2025-71346 | — | — | 0.2% | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected as a duplicate. |
| CVE-2025-41741 | — | — | — | Aug 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-9878 | MEDIUM | 6.4 | — | Aug 25, 2026 | The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2025-26238 | HIGH | 8.1 | — | Aug 24, 2026 | In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. |
| CVE-2025-26237 | HIGH | 8.1 | — | Aug 24, 2026 | D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b... |
| CVE-2025-36940 | HIGH | 8.8 | — | Aug 24, 2026 | Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U... |
| CVE-2025-36939 | MEDIUM | 5.7 | — | Aug 24, 2026 | Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread net... |
| CVE-2025-68825 | HIGH | 7.5 | — | Aug 24, 2026 | HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta... |
| CVE-2025-68833 | MEDIUM | 5.3 | — | Aug 24, 2026 | HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker u... |
| CVE-2025-63080 | HIGH | 8.5 | — | Aug 24, 2026 | Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform o... |
| CVE-2025-3127 | — | — | — | Aug 21, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-2795 | — | — | — | Aug 21, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-15671 | MEDIUM | 5.4 | — | Aug 21, 2026 | The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now