LiveActive security incident?Get immediate response
CVE archive

August 2025

Browse CVE records published in August 2025, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 3504 matching CVEs · Page 2 of 71.

Medium · CVSS 5.3

CVE-2025-14602: Weak File Name Generation in vsDesk

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.

Published Aug 20, 2026 · Updated Aug 20, 2026

High · CVSS 8.8

CVE-2025-14603: Use of user input in raw SQL queries in vsDesk leading to blind SQL injection

The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.  Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.

Published Aug 19, 2026 · Updated Aug 19, 2026

Critical · CVSS 9.3

CVE-2025-14600: Admin Account Takeover via Path Traversal in vsDesk

An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.

Published Aug 19, 2026 · Updated Aug 19, 2026

Medium · CVSS 4.3

CVE-2025-11729: PPWP: Password Protect Pages, Posts & Full or Partial Content <= 1.9.15 - Improper Authorization To Authenticated (Contributor+) Master Password Exposure

The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve a master-password and access any password-protected content.

Published Aug 18, 2026 · Updated Aug 19, 2026

Critical · CVSS 9.8

CVE-2025-25256: An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability...

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions, FortiSIEM 6.3 all versions, FortiSIEM 6.2 all versions, FortiSIEM 6.1 all versions, FortiSIEM 5.4 all versions, FortiSIEM 5.3 all versions, FortiSIEM 5.2 all versions, FortiSIEM 5.1 all versions, FortiSIEM 5.0 all versions, FortiSIEM 4.10 all versions, FortiSIEM 4.9 all versions, FortiSIEM 4.7 all versions allows an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.

Published Aug 12, 2025 · Updated Aug 18, 2026

High · CVSS 7.4

CVE-2025-27770: UpTrain vulnerable to Remote code execution at `/create_project`

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.

Published Aug 17, 2026 · Updated Aug 18, 2026

High · CVSS 7.4

CVE-2025-27771: Uptrain vulnerable to remote code execution via `/add_prompts` endpoint

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.

Published Aug 17, 2026 · Updated Aug 17, 2026

High · CVSS 7.1

CVE-2025-7639: AVEVA Enterprise SCADA Deserialization of Untrusted Data

The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".

Published Aug 14, 2026 · Updated Aug 17, 2026

High · CVSS 7.4

CVE-2025-27772: Uptrain vulnerable to remote code execution via `/new_run` endpoint

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code execution via the `checks` and `metadata` parameters. Any user that has access to UpTrain and a valid authentication method may be able to execute arbitrary code in the context of the host running UpTrain, which in most cases will be the docker container as suggested by the documentation. As of time of publication, no known patch is available.

Published Aug 17, 2026 · Updated Aug 17, 2026

Medium · CVSS 4.3

CVE-2025-10308: Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset

The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Published Aug 14, 2026 · Updated Aug 17, 2026

Medium · CVSS 4.3

CVE-2025-10005: Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.20 via the ppw_free_set_password AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to update the password on any password protected post and subsequently access the content.

Published Aug 16, 2026 · Updated Aug 17, 2026

High · CVSS 8.1

CVE-2025-58375: Frappe has potential SQL Injection due to missing validation

Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.

Published Aug 7, 2026 · Updated Aug 17, 2026

High · CVSS 7.7

CVE-2025-27621: UpTrain has a Constant Default API Key

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user with a static username, where the username is also used as the default API key. The UpTrain backend also has an open CORS policy. Using these two primitives, any website can make a authenticated cross-origin request to the UpTrain instance by providing the default API key in the header `uptrain-access-token`. This issue may allow arbitrary websites to perform privileged operations on the UpTrain instance, as if they were the default logged in user. As of time of publication, no known patches are available.

Published Aug 17, 2026 · Updated Aug 17, 2026

Critical · CVSS 9.3

CVE-2025-31114: Fooocus webui vulnerable to Remote Code Execution

Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.

Published Aug 11, 2026 · Updated Aug 17, 2026

Medium · CVSS 5.1

CVE-2025-71405: go-chi chi before v5.2.2 Open Redirect via RedirectSlashes

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.

Published Aug 14, 2026 · Updated Aug 14, 2026

Medium · CVSS 5.6

CVE-2025-62314: HCL AION is affected by multiple security vulnerabilities.

HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.

Published Aug 13, 2026 · Updated Aug 13, 2026

Low · CVSS 3.7

CVE-2025-62318: HCL AION is affected by multiple security vulnerabilities.

HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.

Published Aug 13, 2026 · Updated Aug 13, 2026

Low · CVSS 3.4

CVE-2025-62315: HCL AION is affected by multiple security vulnerabilities.

HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.

Published Aug 13, 2026 · Updated Aug 13, 2026

Medium · CVSS 4.7

CVE-2025-52640: HCL AION is affected by multiple security vulnerabilities.

HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions.

Published Aug 13, 2026 · Updated Aug 13, 2026

High · CVSS 8.4

CVE-2025-59323: CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a...

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege.

Published Aug 12, 2026 · Updated Aug 13, 2026

Critical · CVSS 9.8

CVE-2025-41769: Unauthenticated Buffer Overflow in PROFINET Service

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

Published Aug 12, 2026 · Updated Aug 13, 2026

Medium · CVSS 6.9

CVE-2025-15684: Open5GS CER init.c diam_log_func assertion

A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/common/init.c of the component CER Handler. The manipulation results in reachable assertion. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 2.7.7 is able to address this issue. The patch is identified as c1a803516a3c0485696cb9bcca7a80ad857c7383. It is advisable to upgrade the affected component.

Published Aug 12, 2026 · Updated Aug 13, 2026

Low · CVSS 3.3

CVE-2025-9486: Incorrect Privilege Assignment in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.

Published Aug 12, 2026 · Updated Aug 13, 2026

High · CVSS 7.2

CVE-2025-59319: CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot...

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.

Published Aug 12, 2026 · Updated Aug 12, 2026

High · CVSS 8.6

CVE-2025-30241: OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions.  An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.

Published Aug 10, 2026 · Updated Aug 12, 2026

Medium · CVSS 4.3

CVE-2025-35987: Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestati...

Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (low) impacts.

Published Aug 11, 2026 · Updated Aug 12, 2026

Medium · CVSS 4.5

CVE-2025-35973: Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal O...

Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

Published Aug 11, 2026 · Updated Aug 12, 2026

Medium · CVSS 5.1

CVE-2025-30240: Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in multiple TP-Link Aginet Devices

The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.

Published Aug 10, 2026 · Updated Aug 12, 2026

High · CVSS 8.8

CVE-2025-15683: Multiple Unauthenticated Denial-of-Service Conditions

TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attacker can invoke specific HTTP endpoints to reboot or reset the device, clear application data, or terminate the web server through a segmentation fault. In addition, multiple action endpoints process attacker-controlled parameters using unsafe string operations such as sprintf() and strcat() without adequate bounds checking, allowing crafted input to trigger buffer overflows and crash the web server. The affected endpoints include onRestart, onReset, ClearData, uploadInvFile, getIndiaRPData, YearCaparity, TotalfaultData, recordData, InvHistoryData, CollectHistoryData, InvFaultData, GetPortTableByParm, and UpdatePortConfig.

Published Aug 10, 2026 · Updated Aug 12, 2026

High · CVSS 8.7

CVE-2025-15682: Unauthenticated Resource Exhaustion

TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can send PUT requests to the /tmp/ endpoint, causing the web server to create persistent files containing attacker-controlled data under /opt/myapp/webserver/. The generated files are not removed because the web server attempts to move them into a non-existent directory. Repeated requests can therefore exhaust available storage and cause a denial-of-service condition.

Published Aug 10, 2026 · Updated Aug 12, 2026

Critical · CVSS 9.2

CVE-2025-15681: Insufficient Webserver Authentication

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauthenticated attacker can directly access protected functionality through the /index.asp endpoint without providing valid credentials. This allows the attacker to access functionality intended for authenticated users and may expose or modify device configuration and data. Logging out from the bypassed state can additionally cause the web server to crash.

Published Aug 10, 2026 · Updated Aug 12, 2026

Low · CVSS 2.4

CVE-2025-15680: Information Disclosure via UART

TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device.

Published Aug 10, 2026 · Updated Aug 12, 2026

Critical · CVSS 9.3

CVE-2025-13294: Unauthenticated SQL Injection

An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters directly into SQLite queries without sufficient validation or parameterization. A remote unauthenticated attacker can exploit these endpoints to read, modify, or delete data stored in the device's CCU.db database.

Published Aug 10, 2026 · Updated Aug 12, 2026

Critical · CVSS 9.3

CVE-2025-13293: Backdoor / default root credentials

A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level access to the device via the exposed SSH service. The root password can be recovered from the password hash stored in /etc/shadow and used to authenticate to the SSH service. Successful exploitation provides full administrative control of the affected device.

Published Aug 10, 2026 · Updated Aug 12, 2026

Medium · CVSS 5.3

CVE-2025-15686: Open5GS HSS Service fd_msg_sess_get denial of service

A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the component HSS Service. Such manipulation of the argument Session-Id leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project locked and limited conversation to collaborators.

Published Aug 12, 2026 · Updated Aug 12, 2026

High · CVSS 8.7

CVE-2025-41770: Unauthenticated Denial of Service

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

Published Aug 12, 2026 · Updated Aug 12, 2026

High · CVSS 7

CVE-2025-31936: Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when us...

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Published Aug 11, 2026 · Updated Aug 12, 2026

Medium · CVSS 4.3

CVE-2025-31938: Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processor...

Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

Published Aug 11, 2026 · Updated Aug 12, 2026

Medium · CVSS 5.6

CVE-2025-31356: Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) wit...

Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without any user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and no effect on availability. Subsequent system impacts include reduced confidentiality (low), integrity (low), and no effect on availability.

Published Aug 11, 2026 · Updated Aug 12, 2026