2025 CVE Vulnerabilities
45,254 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50977 | MEDIUM | 6.1 | 0.3% | Aug 27, 2025 | A template injection vulnerability leading to reflected cross-site scripting (XSS) has been identified in version 1.7.1,... |
| CVE-2025-50428 | CRITICAL | 9.8 | 1.6% | Aug 27, 2025 | In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. ... |
| CVE-2025-34161 | HIGH | 8.8 | 3.7% | Aug 27, 2025 | Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deplo... |
| CVE-2025-34159 | HIGH | 8.8 | 0.9% | Aug 27, 2025 | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application d... |
| CVE-2025-34157 | CRITICAL | 9 | 0.4% | Aug 27, 2025 | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project ... |
| CVE-2025-20348 | MEDIUM | 5 | 0.3% | Aug 27, 2025 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co... |
| CVE-2025-20347 | MEDIUM | 5.4 | 0.2% | Aug 27, 2025 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co... |
| CVE-2025-20344 | HIGH | 7.2 | 0.5% | Aug 27, 2025 | A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attack... |
| CVE-2025-20342 | MEDIUM | 5.4 | 0.2% | Aug 27, 2025 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll... |
| CVE-2025-20317 | HIGH | 7.1 | 0.5% | Aug 27, 2025 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll... |
| CVE-2025-20296 | MEDIUM | 5.4 | 0.2% | Aug 27, 2025 | A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote... |
| CVE-2025-20295 | MEDIUM | 6 | 0.2% | Aug 27, 2025 | A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrativ... |
| CVE-2025-20294 | MEDIUM | 6.5 | 1.2% | Aug 27, 2025 | Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an auth... |
| CVE-2025-20292 | MEDIUM | 4.4 | 3.2% | Aug 27, 2025 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute a command inj... |
| CVE-2025-20290 | MEDIUM | 5.5 | 0.1% | Aug 27, 2025 | A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Se... |
| CVE-2025-20262 | MEDIUM | 5 | 0.3% | Aug 27, 2025 | A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and C... |
| CVE-2025-20241 | HIGH | 7.4 | 0.3% | Aug 27, 2025 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexu... |
| CVE-2025-54598 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete al... |
| CVE-2025-50984 | MEDIUM | 5.3 | 0.3% | Aug 27, 2025 | diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticse... |
| CVE-2025-50983 | HIGH | 8.3 | 0.3% | Aug 27, 2025 | SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4... |
| CVE-2025-50978 | MEDIUM | 6.1 | 0.3% | Aug 27, 2025 | In Gitblit v1.7.1, a reflected cross-site scripting (XSS) vulnerability exists in the way repository path names are hand... |
| CVE-2025-9533 | CRITICAL | 9.8 | 9.2% | Aug 27, 2025 | A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /form... |
| CVE-2025-53105 | HIGH | 7.5 | 0.3% | Aug 27, 2025 | GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that... |
| CVE-2025-52122 | CRITICAL | 9.8 | 0.6% | Aug 27, 2025 | Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability... |
| CVE-2025-50989 | CRITICAL | 9.1 | 8.0% | Aug 27, 2025 | OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now