2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26476 | MEDIUM | 5.5 | 0.1% | Aug 4, 2025 | Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerabi... |
| CVE-2025-21120 | MEDIUM | 6.5 | 0.3% | Aug 4, 2025 | Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Si... |
| CVE-2025-8520 | MEDIUM | 4.7 | 0.3% | Aug 4, 2025 | A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of... |
| CVE-2025-8519 | LOW | 2.7 | 0.4% | Aug 4, 2025 | A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of th... |
| CVE-2025-51390 | CRITICAL | 9.8 | 2.2% | Aug 4, 2025 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter... |
| CVE-2025-46206 | MEDIUM | 6.5 | 0.4% | Aug 4, 2025 | An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion... |
| CVE-2025-34147 | CRITICAL | 9.4 | 1.1% | Aug 4, 2025 | An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ... |
| CVE-2025-8518 | HIGH | 7.2 | 1.3% | Aug 4, 2025 | A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function S... |
| CVE-2025-51535 | CRITICAL | 9.1 | 0.4% | Aug 4, 2025 | Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability. |
| CVE-2025-51534 | HIGH | 8.1 | 0.4% | Aug 4, 2025 | A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers ... |
| CVE-2025-50422 | LOW | 2.9 | 0.2% | Aug 4, 2025 | Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_f... |
| CVE-2025-50420 | MEDIUM | 6.5 | 0.3% | Aug 4, 2025 | An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via ... |
| CVE-2025-44963 | HIGH | 8.1 | 0.6% | Aug 4, 2025 | RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded ... |
| CVE-2025-44962 | MEDIUM | 4.3 | 0.7% | Aug 4, 2025 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files. |
| CVE-2025-44961 | HIGH | 8.8 | 2.1% | Aug 4, 2025 | In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided b... |
| CVE-2025-44960 | HIGH | 8.8 | 1.8% | Aug 4, 2025 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route. |
| CVE-2025-44958 | HIGH | 7.5 | 0.3% | Aug 4, 2025 | RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format. |
| CVE-2025-44957 | HIGH | 8.8 | 0.8% | Aug 4, 2025 | Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP hea... |
| CVE-2025-44954 | CRITICAL | 9.8 | 0.7% | Aug 4, 2025 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account. |
| CVE-2025-8517 | MEDIUM | 6.3 | 0.6% | Aug 4, 2025 | A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in sessi... |
| CVE-2025-8516 | MEDIUM | 5.5 | 0.9% | Aug 4, 2025 | A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects ... |
| CVE-2025-5988 | MEDIUM | 5.3 | 0.2% | Aug 4, 2025 | A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests f... |
| CVE-2025-44955 | HIGH | 8.8 | 0.4% | Aug 4, 2025 | RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password. |
| CVE-2025-38739 | MEDIUM | 5.3 | 0.4% | Aug 4, 2025 | Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remo... |
| CVE-2025-51536 | CRITICAL | 9.8 | 0.5% | Aug 4, 2025 | Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now