2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8671 | HIGH | 7.5 | 4.6% | Aug 13, 2025 | A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architect... |
| CVE-2025-48989 | HIGH | 7.5 | 3.4% | Aug 13, 2025 | Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack... |
| CVE-2025-55280 | MEDIUM | 5.2 | 0.1% | Aug 13, 2025 | This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plai... |
| CVE-2025-55279 | MEDIUM | 6.9 | 0.2% | Aug 13, 2025 | This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. A... |
| CVE-2025-54465 | MEDIUM | 6.8 | 0.2% | Aug 13, 2025 | This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the... |
| CVE-2025-54464 | HIGH | 7 | 0.1% | Aug 13, 2025 | This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device f... |
| CVE-2025-8916 | MEDIUM | 6.3 | 0.4% | Aug 13, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on... |
| CVE-2025-8914 | HIGH | 7.5 | 0.4% | Aug 13, 2025 | Organization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote at... |
| CVE-2025-8913 | CRITICAL | 9.8 | 0.6% | Aug 13, 2025 | Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated re... |
| CVE-2025-8912 | HIGH | 8.7 | 0.5% | Aug 13, 2025 | Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated... |
| CVE-2025-8911 | MEDIUM | 6.1 | 0.3% | Aug 13, 2025 | Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthen... |
| CVE-2025-8910 | MEDIUM | 6.1 | 0.3% | Aug 13, 2025 | Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthen... |
| CVE-2025-8909 | HIGH | 7.1 | 0.6% | Aug 13, 2025 | Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attacker... |
| CVE-2025-55345 | HIGH | 8.8 | 0.8% | Aug 13, 2025 | Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file o... |
| CVE-2025-8762 | MEDIUM | 6.8 | 0.2% | Aug 13, 2025 | A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the comp... |
| CVE-2025-8761 | HIGH | 7.7 | 6.4% | Aug 13, 2025 | A vulnerability has been found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This vulnerability affects unknown code of the co... |
| CVE-2025-8760 | CRITICAL | 9.8 | 0.7% | Aug 13, 2025 | A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the co... |
| CVE-2025-6184 | HIGH | 8.8 | 0.3% | Aug 13, 2025 | The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection ... |
| CVE-2025-6715 | CRITICAL | 9.8 | 0.5% | Aug 13, 2025 | The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes... |
| CVE-2025-7384 | CRITICAL | 9.8 | 1.6% | Aug 13, 2025 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in ... |
| CVE-2025-8891 | MEDIUM | 4.3 | 0.2% | Aug 13, 2025 | The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to m... |
| CVE-2025-8491 | MEDIUM | 4.3 | 0.2% | Aug 13, 2025 | The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-0818 | MEDIUM | 6.5 | 0.7% | Aug 13, 2025 | Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various vers... |
| CVE-2025-8901 | HIGH | 8.8 | 0.3% | Aug 13, 2025 | Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds... |
| CVE-2025-8882 | HIGH | 8.8 | 0.2% | Aug 13, 2025 | Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now