2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8941 | HIGH | 7.8 | 0.3% | Aug 13, 2025 | A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local user... |
| CVE-2025-55163 | HIGH | 7.5 | 1.0% | Aug 13, 2025 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, N... |
| CVE-2025-54809 | HIGH | 8.8 | 0.2% | Aug 13, 2025 | F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Sof... |
| CVE-2025-54500 | MEDIUM | 5.3 | 0.5% | Aug 13, 2025 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to bre... |
| CVE-2025-53859 | MEDIUM | 6.3 | 0.4% | Aug 13, 2025 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated at... |
| CVE-2025-52585 | HIGH | 8.7 | 0.3% | Aug 13, 2025 | When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diff... |
| CVE-2025-51691 | MEDIUM | 6.1 | 0.4% | Aug 13, 2025 | Cross-Site Scripting (XSS) vulnerability found in MarkTwo commit e3a1d3f90cce4ea9c26efcbbf3a1cbfb9dcdb298 (May 2025) all... |
| CVE-2025-50690 | MEDIUM | 6.1 | 0.2% | Aug 13, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in SpatialReference.org (OSGeo/spatialreference.org) versions prior to... |
| CVE-2025-50635 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_... |
| CVE-2025-50251 | CRITICAL | 9.1 | 0.3% | Aug 13, 2025 | Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery. |
| CVE-2025-48500 | HIGH | 7.3 | 0.1% | Aug 13, 2025 | A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, aut... |
| CVE-2025-46405 | HIGH | 8.7 | 0.3% | Aug 13, 2025 | When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management M... |
| CVE-2025-55668 | MEDIUM | 6.5 | 0.8% | Aug 13, 2025 | Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 thr... |
| CVE-2025-55160 | MEDIUM | 5.3 | 0.4% | Aug 13, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2025-55154 | HIGH | 7.8 | 0.9% | Aug 13, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2025-55005 | MEDIUM | 5.5 | 0.2% | Aug 13, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1,... |
| CVE-2025-55004 | MEDIUM | 4.3 | 0.5% | Aug 13, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1,... |
| CVE-2025-54791 | MEDIUM | 5.3 | 0.2% | Aug 13, 2025 | OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when rese... |
| CVE-2025-54382 | HIGH | 8.8 | 5.4% | Aug 13, 2025 | Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (R... |
| CVE-2025-54074 | CRITICAL | 9.8 | 2.1% | Aug 13, 2025 | Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio ... |
| CVE-2025-52392 | MEDIUM | 5.4 | 0.8% | Aug 13, 2025 | Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout m... |
| CVE-2025-52386 | MEDIUM | 5.4 | 0.2% | Aug 13, 2025 | CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file |
| CVE-2025-32451 | HIGH | 8.8 | 0.5% | Aug 13, 2025 | A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A sp... |
| CVE-2025-8908 | CRITICAL | 9.8 | 0.3% | Aug 13, 2025 | A vulnerability was determined in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. Affected by this ... |
| CVE-2025-8907 | HIGH | 7 | 0.1% | Aug 13, 2025 | A vulnerability was found in H3C M2 NAS V100R006. Affected by this vulnerability is an unknown functionality of the comp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now