2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55137 | HIGH | 7.4 | 0.3% | Aug 7, 2025 | LinkJoin through 882f196 mishandles lacks type checking in password reset. |
| CVE-2025-54397 | MEDIUM | 4.3 | 0.2% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Se... |
| CVE-2025-54396 | MEDIUM | 5.4 | 0.2% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated u... |
| CVE-2025-54395 | MEDIUM | 6.1 | 0.2% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configu... |
| CVE-2025-54394 | MEDIUM | 5.3 | 0.3% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credenti... |
| CVE-2025-54393 | MEDIUM | 5.4 | 0.2% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authent... |
| CVE-2025-54392 | MEDIUM | 6.1 | 0.3% | Aug 7, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d... |
| CVE-2025-34152 | CRITICAL | 9.4 | 61.7% | Aug 7, 2025 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ... |
| CVE-2025-34151 | CRITICAL | 9.4 | 3.8% | Aug 7, 2025 | A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M30... |
| CVE-2025-34150 | CRITICAL | 9.4 | 1.4% | Aug 7, 2025 | The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to comm... |
| CVE-2025-34149 | CRITICAL | 9.4 | 1.5% | Aug 7, 2025 | A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 conf... |
| CVE-2025-34148 | CRITICAL | 9.4 | 1.3% | Aug 7, 2025 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ... |
| CVE-2025-24000 | HIGH | 8.8 | 0.5% | Aug 7, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authenti... |
| CVE-2025-7054 | MEDIUM | 6.5 | 0.4% | Aug 7, 2025 | Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_... |
| CVE-2025-55136 | MEDIUM | 5.7 | 0.1% | Aug 7, 2025 | ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because j... |
| CVE-2025-55135 | MEDIUM | 6.4 | 0.2% | Aug 7, 2025 | In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userCont... |
| CVE-2025-55134 | MEDIUM | 6.4 | 0.2% | Aug 7, 2025 | In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js. |
| CVE-2025-55133 | MEDIUM | 6.4 | 0.2% | Aug 7, 2025 | In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManag... |
| CVE-2025-47907 | HIGH | 7 | 0.3% | Aug 7, 2025 | Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method ... |
| CVE-2025-44779 | MEDIUM | 6.6 | 0.2% | Aug 7, 2025 | An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/... |
| CVE-2025-50952 | MEDIUM | 6.5 | 0.2% | Aug 7, 2025 | openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c. |
| CVE-2025-47188 | MEDIUM | 6.5 | 48.5% | Aug 7, 2025 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th... |
| CVE-2025-8533 | MEDIUM | 6.9 | 0.4% | Aug 7, 2025 | A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client author... |
| CVE-2025-35970 | HIGH | 8.7 | 0.4% | Aug 7, 2025 | On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from t... |
| CVE-2025-29866 | HIGH | 8.8 | 0.3% | Aug 7, 2025 | : External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now