2025 CVE Vulnerabilities
45,253 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58067 | MEDIUM | 4.2 | 0.2% | Aug 29, 2025 | Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect ... |
| CVE-2025-58066 | MEDIUM | 5.3 | 0.3% | Aug 29, 2025 | nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. In versions between 1... |
| CVE-2025-9673 | MEDIUM | 5.3 | 0.1% | Aug 29, 2025 | A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an ... |
| CVE-2025-9672 | MEDIUM | 5.3 | 0.1% | Aug 29, 2025 | A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file A... |
| CVE-2025-9671 | MEDIUM | 5.3 | 0.1% | Aug 29, 2025 | A weakness has been identified in UAB Paytend App up to 2.1.9 on Android. This impacts an unknown function of the file A... |
| CVE-2025-56577 | HIGH | 8.4 | 0.1% | Aug 29, 2025 | An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryp... |
| CVE-2025-9670 | MEDIUM | 5.5 | 0.5% | Aug 29, 2025 | A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src... |
| CVE-2025-9669 | CRITICAL | 9.8 | 0.4% | Aug 29, 2025 | A vulnerability has been found in Jinher OA 1.0. This issue affects some unknown processing of the file GetTreeDate.aspx... |
| CVE-2025-9667 | HIGH | 8.8 | 0.4% | Aug 29, 2025 | A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delet... |
| CVE-2025-43773 | CRITICAL | 9.1 | 0.3% | Aug 29, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024... |
| CVE-2025-9666 | HIGH | 8.8 | 0.3% | Aug 29, 2025 | A security vulnerability has been detected in code-projects Simple Grading System 1.0. Affected by this issue is some un... |
| CVE-2025-9665 | HIGH | 8.8 | 0.4% | Aug 29, 2025 | A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this vulnerability is an unknown ... |
| CVE-2025-9377 | HIGH | 7.2 | 11.7% | Aug 29, 2025 | The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7... |
| CVE-2025-58158 | HIGH | 8.8 | 0.5% | Aug 29, 2025 | Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Develope... |
| CVE-2025-52861 | HIGH | 7 | 0.6% | Aug 29, 2025 | A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account,... |
| CVE-2025-52856 | CRITICAL | 9.8 | 0.6% | Aug 29, 2025 | An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploi... |
| CVE-2025-44033 | CRITICAL | 9.8 | 0.6% | Aug 29, 2025 | SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirec... |
| CVE-2025-44015 | HIGH | 8.4 | 0.9% | Aug 29, 2025 | A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network acc... |
| CVE-2025-33038 | MEDIUM | 6.5 | 0.4% | Aug 29, 2025 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-33037 | MEDIUM | 6.5 | 0.4% | Aug 29, 2025 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-33036 | MEDIUM | 6.5 | 0.4% | Aug 29, 2025 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-33033 | MEDIUM | 6.5 | 0.4% | Aug 29, 2025 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-33032 | MEDIUM | 4.9 | 0.5% | Aug 29, 2025 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ... |
| CVE-2025-30278 | HIGH | 8.8 | 0.2% | Aug 29, 2025 | An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a... |
| CVE-2025-30277 | HIGH | 8.8 | 0.2% | Aug 29, 2025 | An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now