2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-3671 | HIGH | 8.8 | 0.7% | Aug 16, 2025 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u... |
| CVE-2025-49895 | MEDIUM | 6.5 | 0.1% | Aug 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This i... |
| CVE-2025-55284 | HIGH | 7.5 | 0.4% | Aug 16, 2025 | Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prom... |
| CVE-2025-55286 | HIGH | 7.3 | 0.1% | Aug 16, 2025 | z2d is a pure Zig 2D graphics library. z2d v0.7.0 released with a new multi-sample anti-aliasing (MSAA) method, which us... |
| CVE-2025-52621 | HIGH | 7.5 | 0.1% | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning. The BigFix SaaS's HTTP responses were observe... |
| CVE-2025-52620 | MEDIUM | 5.4 | 0.2% | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload func... |
| CVE-2025-52619 | MEDIUM | 5.3 | 0.3% | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, err... |
| CVE-2025-52618 | CRITICAL | 9.8 | 0.3% | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a SQL injection vulnerability. The vulnerability allows potential... |
| CVE-2025-43201 | MEDIUM | 6.2 | 0.1% | Aug 15, 2025 | This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may ... |
| CVE-2025-8959 | HIGH | 7.5 | 0.5% | Aug 15, 2025 | HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized rea... |
| CVE-2025-44201 | — | — | — | Aug 15, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2025-36088 | MEDIUM | 5.4 | 0.2% | Aug 15, 2025 | IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This... |
| CVE-2025-43490 | HIGH | 8.4 | 0.1% | Aug 15, 2025 | A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support... |
| CVE-2025-55285 | LOW | 2.6 | 0.2% | Aug 15, 2025 | @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1... |
| CVE-2025-9060 | CRITICAL | 9.1 | 0.5% | Aug 15, 2025 | A vulnerability has been found in the MSoft MFlash application that allows execution of arbitrary code on the server... |
| CVE-2025-8996 | MEDIUM | 4.3 | 0.2% | Aug 15, 2025 | Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue af... |
| CVE-2025-8995 | CRITICAL | 9.8 | 0.5% | Aug 15, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati... |
| CVE-2025-8675 | HIGH | 8.8 | 0.2% | Aug 15, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This i... |
| CVE-2025-8362 | MEDIUM | 6.1 | 0.2% | Aug 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag M... |
| CVE-2025-8361 | HIGH | 7.6 | 0.3% | Aug 15, 2025 | Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: f... |
| CVE-2025-8092 | HIGH | 7.6 | 0.3% | Aug 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con... |
| CVE-2025-7961 | MEDIUM | 6.9 | 0.2% | Aug 15, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS allows TCC Bypass.This i... |
| CVE-2025-8066 | MEDIUM | 4.8 | 0.4% | Aug 15, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bunkerity Bunker Web on Linux allows Phishing.This ... |
| CVE-2025-55207 | MEDIUM | 5.5 | 0.5% | Aug 15, 2025 | Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerabil... |
| CVE-2025-49898 | HIGH | 7.6 | 0.4% | Aug 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now