2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29366 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | In mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and write_rdram_regs functions, w... |
| CVE-2025-29365 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL. |
| CVE-2025-55573 | HIGH | 8.8 | 0.4% | Aug 22, 2025 | QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2025-36042 | MEDIUM | 5.4 | 0.2% | Aug 22, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenti... |
| CVE-2025-33120 | HIGH | 7.8 | 0.1% | Aug 22, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigure... |
| CVE-2025-51825 | MEDIUM | 6.5 | 0.2% | Aug 22, 2025 | JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/... |
| CVE-2025-50691 | MEDIUM | 5.3 | 0.2% | Aug 22, 2025 | MCSManager 10.5.3 daemon process runs as a root account by default, and its sensitive data (including tokens and termina... |
| CVE-2025-38618 | HIGH | 7.8 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It ... |
| CVE-2025-38617 | MEDIUM | 4.7 | 0.3% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and pac... |
| CVE-2025-38616 | HIGH | 7.1 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS UL... |
| CVE-2025-9331 | MEDIUM | 4.3 | 0.3% | Aug 22, 2025 | The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2025-9259 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9258 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9257 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9256 | HIGH | 7.1 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privilege... |
| CVE-2025-9255 | HIGH | 8.7 | 0.5% | Aug 22, 2025 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitr... |
| CVE-2025-9254 | CRITICAL | 9.8 | 0.6% | Aug 22, 2025 | WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log ... |
| CVE-2025-57896 | MEDIUM | 5.3 | 0.2% | Aug 22, 2025 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-57895 | MEDIUM | 4.3 | 0.1% | Aug 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This iss... |
| CVE-2025-57894 | MEDIUM | 4.3 | 0.2% | Aug 22, 2025 | Missing Authorization vulnerability in ollybach WPPizza wppizza allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-57893 | MEDIUM | 4.3 | 0.1% | Aug 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Re... |
| CVE-2025-57892 | MEDIUM | 4.3 | 0.1% | Aug 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Starr Simple Statistics for Feeds simple-feed-stats allows Cross... |
| CVE-2025-57891 | MEDIUM | 5.9 | 0.2% | Aug 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Recurr... |
| CVE-2025-57890 | MEDIUM | 5.9 | 0.2% | Aug 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sess... |
| CVE-2025-57888 | MEDIUM | 5.3 | 0.2% | Aug 22, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NooTheme Jobmonster noo-jobm... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now