2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55733 | CRITICAL | 9.6 | 0.6% | Aug 19, 2025 | DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click r... |
| CVE-2025-55306 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX F... |
| CVE-2025-55303 | MEDIUM | 6.1 | 0.6% | Aug 19, 2025 | Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimiza... |
| CVE-2025-52338 | MEDIUM | 5.3 | 0.5% | Aug 19, 2025 | An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows... |
| CVE-2025-50891 | HIGH | 7.2 | 0.4% | Aug 19, 2025 | The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary ... |
| CVE-2025-43745 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 t... |
| CVE-2025-43737 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through ... |
| CVE-2025-33008 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vu... |
| CVE-2025-31988 | MEDIUM | 4.8 | 0.2% | Aug 19, 2025 | HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access. |
| CVE-2025-9151 | MEDIUM | 6.3 | 0.3% | Aug 19, 2025 | A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the funct... |
| CVE-2025-9150 | HIGH | 7.3 | 0.3% | Aug 19, 2025 | A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317. Affec... |
| CVE-2025-9149 | CRITICAL | 9.8 | 5.6% | Aug 19, 2025 | A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cg... |
| CVE-2025-8450 | HIGH | 8.2 | 0.3% | Aug 19, 2025 | Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload ... |
| CVE-2025-55295 | MEDIUM | 6.5 | 0.5% | Aug 19, 2025 | qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability e... |
| CVE-2025-55294 | CRITICAL | 9.8 | 1.5% | Aug 19, 2025 | screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue.... |
| CVE-2025-55153 | — | — | — | Aug 19, 2025 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2025-9148 | MEDIUM | 6.3 | 0.3% | Aug 19, 2025 | A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/se... |
| CVE-2025-9147 | MEDIUM | 6.1 | 0.3% | Aug 19, 2025 | A vulnerability has been found in jasonclark getsemantic up to 040c96eb8cf9947488bd01b8de99b607b0519f7d. The impacted el... |
| CVE-2025-54881 | MEDIUM | 5.3 | 0.7% | Aug 19, 2025 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ... |
| CVE-2025-54880 | MEDIUM | 6.1 | 0.3% | Aug 19, 2025 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ... |
| CVE-2025-54411 | MEDIUM | 5.4 | 0.2% | Aug 19, 2025 | Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable t... |
| CVE-2025-52478 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability w... |
| CVE-2025-51506 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKe... |
| CVE-2025-38615 | MEDIUM | 5.5 | 0.2% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: cancle set bad inode after removing name ... |
| CVE-2025-38614 | MEDIUM | 5.5 | 0.2% | Aug 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure tha... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now