2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54927 | MEDIUM | 4.9 | 0.6% | Aug 20, 2025 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c... |
| CVE-2025-54926 | HIGH | 7.2 | 0.8% | Aug 20, 2025 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c... |
| CVE-2025-54925 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data ... |
| CVE-2025-54924 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data ... |
| CVE-2025-54923 | HIGH | 8.7 | 0.6% | Aug 20, 2025 | CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of... |
| CVE-2025-50503 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the O... |
| CVE-2025-32010 | CRITICAL | 9.8 | 0.6% | Aug 20, 2025 | A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A spe... |
| CVE-2025-31355 | CRITICAL | 9.8 | 0.3% | Aug 20, 2025 | A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.11... |
| CVE-2025-30256 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A spe... |
| CVE-2025-27129 | CRITICAL | 9.8 | 2.0% | Aug 20, 2025 | An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. ... |
| CVE-2025-24496 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.1... |
| CVE-2025-24322 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.... |
| CVE-2025-8453 | HIGH | 8.4 | 0.2% | Aug 20, 2025 | CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code exe... |
| CVE-2025-54175 | MEDIUM | 6.1 | 0.2% | Aug 20, 2025 | QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality. An attacker can c... |
| CVE-2025-54174 | MEDIUM | 4.3 | 0.1% | Aug 20, 2025 | QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft spe... |
| CVE-2025-54172 | MEDIUM | 4.8 | 0.2% | Aug 20, 2025 | QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin pri... |
| CVE-2025-4877 | MEDIUM | 4.5 | 0.2% | Aug 20, 2025 | There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer ... |
| CVE-2025-4437 | MEDIUM | 5.7 | 0.2% | Aug 20, 2025 | There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specify... |
| CVE-2025-43750 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-43749 | MEDIUM | 5.3 | 0.2% | Aug 20, 2025 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q... |
| CVE-2025-8102 | MEDIUM | 5.4 | 0.2% | Aug 20, 2025 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-7777 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker... |
| CVE-2025-43742 | MEDIUM | 6.1 | 0.2% | Aug 20, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025... |
| CVE-2025-43741 | MEDIUM | 5.4 | 0.2% | Aug 20, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025... |
| CVE-2025-9173 | — | — | — | Aug 20, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now