2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44643 | HIGH | 8.6 | 0.2% | Aug 4, 2025 | Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R... |
| CVE-2025-36594 | CRITICAL | 9.8 | 0.4% | Aug 4, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.... |
| CVE-2025-30099 | HIGH | 7.8 | 0.4% | Aug 4, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-30098 | MEDIUM | 6.7 | 0.4% | Aug 4, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-30097 | MEDIUM | 6.7 | 0.4% | Aug 4, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-30096 | MEDIUM | 6.7 | 0.4% | Aug 4, 2025 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.... |
| CVE-2025-26065 | HIGH | 7.3 | 0.3% | Aug 4, 2025 | A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb... |
| CVE-2025-8109 | HIGH | 8.8 | 0.4% | Aug 4, 2025 | Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read o... |
| CVE-2025-36607 | HIGH | 7.8 | 0.5% | Aug 4, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authen... |
| CVE-2025-36606 | HIGH | 7.8 | 0.5% | Aug 4, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An... |
| CVE-2025-36605 | MEDIUM | 6.1 | 0.2% | Aug 4, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-... |
| CVE-2025-36604 | CRITICAL | 9.8 | 61.9% | Aug 4, 2025 | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2025-8515 | LOW | 3.7 | 0.3% | Aug 4, 2025 | A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1... |
| CVE-2025-6205 | CRITICAL | 9.1 | 69.2% | Aug 4, 2025 | A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an atta... |
| CVE-2025-6204 | HIGH | 8 | 75.3% | Aug 4, 2025 | An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 throu... |
| CVE-2025-0932 | MEDIUM | 4.3 | 0.2% | Aug 4, 2025 | Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm ... |
| CVE-2025-8341 | MEDIUM | 5 | 0.3% | Aug 4, 2025 | Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafa... |
| CVE-2025-41691 | HIGH | 7.5 | 0.5% | Aug 4, 2025 | An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime system... |
| CVE-2025-41659 | HIGH | 8.3 | 0.2% | Aug 4, 2025 | A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and wri... |
| CVE-2025-41658 | MEDIUM | 5.5 | 0.1% | Aug 4, 2025 | CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to ... |
| CVE-2025-20702 | HIGH | 8.8 | 5.2% | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remo... |
| CVE-2025-20701 | HIGH | 8.8 | 7.7% | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This cou... |
| CVE-2025-20700 | HIGH | 8.8 | 6.2% | Aug 4, 2025 | In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protoc... |
| CVE-2025-48499 | MEDIUM | 6.9 | 0.3% | Aug 4, 2025 | Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printin... |
| CVE-2025-54962 | MEDIUM | 6.4 | 0.2% | Aug 4, 2025 | /edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now