2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46852 | MEDIUM | 5.4 | 0.2% | Aug 20, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-46849 | MEDIUM | 5.4 | 0.2% | Aug 20, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-28041 | HIGH | 8.6 | 0.3% | Aug 20, 2025 | Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive componen... |
| CVE-2025-20345 | MEDIUM | 4.9 | 0.4% | Aug 20, 2025 | A vulnerability in the debug logging function of Cisco Duo Authentication Proxy could allow an authenticated, high-privi... |
| CVE-2025-20269 | MEDIUM | 6.5 | 0.4% | Aug 20, 2025 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2025-20131 | MEDIUM | 4.9 | 0.3% | Aug 20, 2025 | A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with ad... |
| CVE-2025-9233 | MEDIUM | 5.4 | 0.3% | Aug 20, 2025 | A security vulnerability has been detected in Scada-LTS up to 2.7.8.1. Impacted is an unknown function of the file view_... |
| CVE-2025-55751 | MEDIUM | 5.1 | 0.3% | Aug 20, 2025 | OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the Uni... |
| CVE-2025-55732 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Frappe is a full-stack web application framework. Prior to 15.74.2 and 14.96.15, an attacker could implement SQL injecti... |
| CVE-2025-55731 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would nor... |
| CVE-2025-55498 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime fu... |
| CVE-2025-55482 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function. |
| CVE-2025-51991 | HIGH | 8.8 | 3.4% | Aug 20, 2025 | XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, spe... |
| CVE-2025-51990 | MEDIUM | 4.8 | 0.5% | Aug 20, 2025 | XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administra... |
| CVE-2025-50864 | MEDIUM | 6.5 | 0.4% | Aug 20, 2025 | An Origin Validation Error in the elysia-cors library thru 1.3.0 allows attackers to bypass Cross-Origin Resource Sharin... |
| CVE-2025-43748 | MEDIUM | 6.8 | 0.1% | Aug 20, 2025 | Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 202... |
| CVE-2025-36114 | HIGH | 7.5 | 0.5% | Aug 20, 2025 | IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An a... |
| CVE-2025-1142 | MEDIUM | 5.4 | 0.2% | Aug 20, 2025 | IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at... |
| CVE-2025-1139 | MEDIUM | 4.4 | 0.1% | Aug 20, 2025 | IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authoriz... |
| CVE-2025-9074 | CRITICAL | 9.3 | 1.6% | Aug 20, 2025 | A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine ... |
| CVE-2025-8449 | MEDIUM | 4.1 | 0.2% | Aug 20, 2025 | CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticat... |
| CVE-2025-8448 | LOW | 1 | 0.2% | Aug 20, 2025 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized a... |
| CVE-2025-55503 | HIGH | 7.3 | 0.3% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInf... |
| CVE-2025-55499 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTi... |
| CVE-2025-55483 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters mac... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now