2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46658 | CRITICAL | 9.8 | 0.4% | Aug 5, 2025 | An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages. |
| CVE-2025-43979 | HIGH | 7.4 | 5.0% | Aug 5, 2025 | An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute ar... |
| CVE-2025-54874 | CRITICAL | 9.8 | 0.6% | Aug 5, 2025 | OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead... |
| CVE-2025-50707 | CRITICAL | 9.8 | 1.0% | Aug 5, 2025 | An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component |
| CVE-2025-50706 | CRITICAL | 9.8 | 1.0% | Aug 5, 2025 | An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function |
| CVE-2025-47152 | MEDIUM | 6.5 | 0.5% | Aug 5, 2025 | An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396... |
| CVE-2025-46958 | MEDIUM | 5.4 | 0.3% | Aug 5, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-44964 | LOW | 3.9 | 0.1% | Aug 5, 2025 | A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obta... |
| CVE-2025-2611 | CRITICAL | 9.3 | 6.1% | Aug 5, 2025 | The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject she... |
| CVE-2025-29745 | HIGH | 7.5 | 0.4% | Aug 5, 2025 | A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote ser... |
| CVE-2025-27931 | MEDIUM | 6.5 | 0.5% | Aug 5, 2025 | An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using ... |
| CVE-2025-7033 | HIGH | 7.8 | 0.3% | Aug 5, 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re... |
| CVE-2025-7032 | HIGH | 7.8 | 0.3% | Aug 5, 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re... |
| CVE-2025-7025 | HIGH | 7.8 | 0.3% | Aug 5, 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re... |
| CVE-2025-54987 | CRITICAL | 9.8 | 16.9% | Aug 5, 2025 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ... |
| CVE-2025-54948 | CRITICAL | 9.8 | 20.3% | Aug 5, 2025 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ... |
| CVE-2025-8555 | MEDIUM | 5.4 | 0.3% | Aug 5, 2025 | A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown funct... |
| CVE-2025-8554 | MEDIUM | 5.4 | 0.2% | Aug 5, 2025 | A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some... |
| CVE-2025-8553 | MEDIUM | 5.4 | 0.2% | Aug 5, 2025 | A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code ... |
| CVE-2025-8552 | MEDIUM | 5.4 | 0.2% | Aug 5, 2025 | A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the... |
| CVE-2025-8551 | MEDIUM | 5.4 | 0.2% | Aug 5, 2025 | A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some u... |
| CVE-2025-8295 | MEDIUM | 6.4 | 0.2% | Aug 5, 2025 | The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ paramete... |
| CVE-2025-8294 | MEDIUM | 6.4 | 0.2% | Aug 5, 2025 | The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all v... |
| CVE-2025-6207 | HIGH | 8.8 | 0.6% | Aug 5, 2025 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2025-5061 | HIGH | 8.8 | 0.6% | Aug 5, 2025 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now