2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8168 | CRITICAL | 9.8 | 1.5% | Jul 25, 2025 | A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function ... |
| CVE-2025-8167 | MEDIUM | 5.4 | 0.3% | Jul 25, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by ... |
| CVE-2025-46198 | HIGH | 8.8 | 0.6% | Jul 25, 2025 | Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code ... |
| CVE-2025-30135 | CRITICAL | 9.4 | 0.5% | Jul 25, 2025 | An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur.... |
| CVE-2025-8166 | CRITICAL | 9.8 | 0.5% | Jul 25, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a... |
| CVE-2025-8165 | HIGH | 8.8 | 0.5% | Jul 25, 2025 | A vulnerability was found in code-projects Food Review System 1.0 and classified as critical. This issue affects some un... |
| CVE-2025-52455 | MEDIUM | 5.3 | 0.3% | Jul 25, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) all... |
| CVE-2025-52454 | HIGH | 8.2 | 0.3% | Jul 25, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector mod... |
| CVE-2025-52453 | HIGH | 8.2 | 0.3% | Jul 25, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source module... |
| CVE-2025-52452 | HIGH | 8.5 | 0.4% | Jul 25, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Serve... |
| CVE-2025-52449 | HIGH | 8.5 | 0.2% | Jul 25, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible... |
| CVE-2025-52448 | HIGH | 8.1 | 0.3% | Jul 25, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-... |
| CVE-2025-52447 | HIGH | 8.1 | 0.3% | Jul 25, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initi... |
| CVE-2025-52446 | HIGH | 8 | 0.2% | Jul 25, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc a... |
| CVE-2025-8164 | HIGH | 8.8 | 0.4% | Jul 25, 2025 | A vulnerability has been found in code-projects Public Chat Room 1.0 and classified as critical. This vulnerability affe... |
| CVE-2025-8163 | HIGH | 8.8 | 0.4% | Jul 25, 2025 | A vulnerability, which was classified as critical, was found in deerwms deer-wms-2 up to 3.3. This affects an unknown pa... |
| CVE-2025-5449 | MEDIUM | 6.5 | 0.8% | Jul 25, 2025 | A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length... |
| CVE-2025-46199 | CRITICAL | 9.8 | 0.8% | Jul 25, 2025 | Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafte... |
| CVE-2025-8162 | HIGH | 8.8 | 0.4% | Jul 25, 2025 | A vulnerability, which was classified as critical, has been found in deerwms deer-wms-2 up to 3.3. Affected by this issu... |
| CVE-2025-8161 | HIGH | 8.8 | 0.4% | Jul 25, 2025 | A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. Affected by this vulnerability is an u... |
| CVE-2025-54596 | MEDIUM | 4.3 | 0.2% | Jul 25, 2025 | Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the privileges of other user accou... |
| CVE-2025-45960 | MEDIUM | 6.1 | 0.4% | Jul 25, 2025 | Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via t... |
| CVE-2025-45893 | MEDIUM | 6.1 | 0.2% | Jul 25, 2025 | OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog p... |
| CVE-2025-45892 | MEDIUM | 6.1 | 0.2% | Jul 25, 2025 | OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerabil... |
| CVE-2025-45406 | MEDIUM | 6.1 | 0.3% | Jul 25, 2025 | A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scrip... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now