2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53251 | CRITICAL | 9.9 | 0.3% | Aug 21, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP pin-wp allows Upload a Web Shell to a ... |
| CVE-2025-52194 | HIGH | 7.5 | 0.6% | Aug 21, 2025 | A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malf... |
| CVE-2025-50860 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers ... |
| CVE-2025-48956 | HIGH | 7.5 | 0.5% | Aug 21, 2025 | vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Ser... |
| CVE-2025-9302 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the ... |
| CVE-2025-9301 | LOW | 3.3 | 0.1% | Aug 21, 2025 | A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::Repla... |
| CVE-2025-55564 | HIGH | 7.5 | 0.4% | Aug 21, 2025 | Tenda AC15 v15.03.05.19_multi_TD01 has a stack overflow via the list parameter in the fromSetIpMacBind function. |
| CVE-2025-55370 | HIGH | 8.8 | 0.4% | Aug 21, 2025 | Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attacke... |
| CVE-2025-55368 | HIGH | 8.8 | 0.4% | Aug 21, 2025 | Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers t... |
| CVE-2025-55367 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attacke... |
| CVE-2025-55366 | MEDIUM | 5.3 | 0.3% | Aug 21, 2025 | Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily... |
| CVE-2025-51818 | MEDIUM | 5.4 | 0.2% | Aug 21, 2025 | MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute ar... |
| CVE-2025-34158 | HIGH | 8.5 | 0.5% | Aug 21, 2025 | Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spher... |
| CVE-2025-9300 | HIGH | 7.8 | 0.2% | Aug 21, 2025 | A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_pal... |
| CVE-2025-9299 | CRITICAL | 9.8 | 4.3% | Aug 21, 2025 | A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPasseng... |
| CVE-2025-9298 | CRITICAL | 9.8 | 1.0% | Aug 21, 2025 | A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Exec... |
| CVE-2025-9297 | HIGH | 8.8 | 1.0% | Aug 21, 2025 | A vulnerability was detected in Tenda i22 1.0.0.3(4687). This impacts the function formWeixinAuthInfoGet of the file /go... |
| CVE-2025-47184 | MEDIUM | 5.3 | 0.2% | Aug 21, 2025 | An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 ... |
| CVE-2025-9296 | CRITICAL | 9.8 | 0.4% | Aug 21, 2025 | A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admi... |
| CVE-2025-8064 | MEDIUM | 6.4 | 0.2% | Aug 21, 2025 | The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘selector_height’ parame... |
| CVE-2025-8895 | CRITICAL | 9.8 | 0.5% | Aug 21, 2025 | The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied inp... |
| CVE-2025-8023 | MEDIUM | 4.9 | 0.4% | Aug 21, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path trave... |
| CVE-2025-53971 | LOW | 3.8 | 0.2% | Aug 21, 2025 | Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role mod... |
| CVE-2025-49810 | MEDIUM | 4.3 | 0.2% | Aug 21, 2025 | Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thre... |
| CVE-2025-49222 | MEDIUM | 6.8 | 0.3% | Aug 21, 2025 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now