2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45313 | MEDIUM | 6.1 | 0.2% | Aug 13, 2025 | A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbi... |
| CVE-2025-43989 | MEDIUM | 6.5 | 5.8% | Aug 13, 2025 | The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandl... |
| CVE-2025-8921 | CRITICAL | 9.8 | 0.4% | Aug 13, 2025 | A vulnerability has been found in code-projects Job Diary 1.0. Affected by this issue is some unknown functionality of t... |
| CVE-2025-8920 | MEDIUM | 5.4 | 0.3% | Aug 13, 2025 | A vulnerability was identified in Portabilis i-Diario 1.6. Affected by this vulnerability is an unknown functionality of... |
| CVE-2025-8919 | MEDIUM | 4.8 | 0.3% | Aug 13, 2025 | A vulnerability was determined in Portabilis i-Diario up to 1.6. Affected is an unknown function of the file /objetivos-... |
| CVE-2025-8904 | CRITICAL | 9 | 0.3% | Aug 13, 2025 | Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ director... |
| CVE-2025-8770 | MEDIUM | 6.5 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18... |
| CVE-2025-8754 | HIGH | 8.7 | 0.3% | Aug 13, 2025 | Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM z... |
| CVE-2025-7739 | MEDIUM | 5.4 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditio... |
| CVE-2025-7734 | MEDIUM | 5.4 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2... |
| CVE-2025-6186 | MEDIUM | 5.4 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that... |
| CVE-2025-5819 | MEDIUM | 5 | 0.2% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.... |
| CVE-2025-50946 | MEDIUM | 6.5 | 1.3% | Aug 13, 2025 | OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/a... |
| CVE-2025-50617 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046ed68 function of the cgite... |
| CVE-2025-50616 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046f984 function of the cgite... |
| CVE-2025-50615 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgite... |
| CVE-2025-45317 | MEDIUM | 6.5 | 0.3% | Aug 13, 2025 | A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute ar... |
| CVE-2025-45316 | MEDIUM | 6.1 | 0.3% | Aug 13, 2025 | A cross-site scripting (XSS) vulnerability in the TextBlockModule.php component of hortusfox-web v4.4 allows attackers t... |
| CVE-2025-45315 | MEDIUM | 5.4 | 0.2% | Aug 13, 2025 | A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers ... |
| CVE-2025-45314 | MEDIUM | 6.1 | 0.3% | Aug 13, 2025 | A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute a... |
| CVE-2025-2937 | MEDIUM | 6.5 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.... |
| CVE-2025-2614 | MEDIUM | 6.5 | 0.3% | Aug 13, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.... |
| CVE-2025-2498 | MEDIUM | 4.3 | 0.2% | Aug 13, 2025 | An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2... |
| CVE-2025-23306 | HIGH | 7.8 | 0.2% | Aug 13, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an ... |
| CVE-2025-23305 | HIGH | 7.8 | 0.2% | Aug 13, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a co... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now