2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33077 | HIGH | 8.8 | 0.4% | Jul 23, 2025 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused b... |
| CVE-2025-33076 | HIGH | 8.8 | 0.4% | Jul 23, 2025 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused b... |
| CVE-2025-33020 | HIGH | 7.5 | 0.1% | Jul 23, 2025 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that ... |
| CVE-2025-54090 | MEDIUM | 6.3 | 0.7% | Jul 23, 2025 | A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recomm... |
| CVE-2025-46099 | HIGH | 7.2 | 0.5% | Jul 23, 2025 | In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module direc... |
| CVE-2025-40599 | CRITICAL | 9.1 | 11.6% | Jul 23, 2025 | An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote att... |
| CVE-2025-4411 | MEDIUM | 6.5 | 0.3% | Jul 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom In... |
| CVE-2025-54297 | HIGH | 7 | 0.2% | Jul 23, 2025 | A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered. |
| CVE-2025-54296 | HIGH | 7 | 0.2% | Jul 23, 2025 | A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered. |
| CVE-2025-54295 | MEDIUM | 5.1 | 0.3% | Jul 23, 2025 | A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered. |
| CVE-2025-54294 | CRITICAL | 9.3 | 0.3% | Jul 23, 2025 | A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to e... |
| CVE-2025-50127 | HIGH | 8.5 | 0.3% | Jul 23, 2025 | A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execu... |
| CVE-2025-4296 | MEDIUM | 4.7 | 0.2% | Jul 23, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing. This iss... |
| CVE-2025-27930 | MEDIUM | 5.4 | 0.4% | Jul 23, 2025 | Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in th... |
| CVE-2025-53882 | MEDIUM | 4.8 | 0.1% | Jul 23, 2025 | A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3... |
| CVE-2025-41687 | CRITICAL | 9.8 | 0.7% | Jul 23, 2025 | An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full acces... |
| CVE-2025-41684 | HIGH | 8.8 | 0.7% | Jul 23, 2025 | An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of ... |
| CVE-2025-41683 | HIGH | 8.8 | 0.7% | Jul 23, 2025 | An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of ... |
| CVE-2025-8070 | CRITICAL | 9.2 | 0.2% | Jul 23, 2025 | The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allow... |
| CVE-2025-31701 | HIGH | 8.1 | 0.8% | Jul 23, 2025 | A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending sp... |
| CVE-2025-31700 | HIGH | 8.1 | 0.8% | Jul 23, 2025 | A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending sp... |
| CVE-2025-6174 | MEDIUM | 6.1 | 0.5% | Jul 23, 2025 | The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_styleshe... |
| CVE-2025-54455 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ... |
| CVE-2025-54454 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ... |
| CVE-2025-54453 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now