2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54452 | CRITICAL | 9.8 | 0.4% | Jul 23, 2025 | Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue ... |
| CVE-2025-54451 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows... |
| CVE-2025-54450 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54449 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54448 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54447 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54446 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54445 | CRITICAL | 9.8 | 9.2% | Jul 23, 2025 | Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Ser... |
| CVE-2025-54444 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54443 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54442 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54441 | HIGH | 8.8 | 7.4% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54440 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54439 | HIGH | 8.8 | 6.9% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54438 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-8022 | — | — | — | Jul 23, 2025 | Rejected reason: Bun Shell does not invoke /bin/sh, or any other interpreter, for template literals created with the $ f... |
| CVE-2025-8021 | HIGH | 7.7 | 0.8% | Jul 23, 2025 | All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the... |
| CVE-2025-8020 | HIGH | 8.2 | 0.3% | Jul 23, 2025 | All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provid... |
| CVE-2025-43881 | MEDIUM | 5.3 | 0.3% | Jul 23, 2025 | Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. ... |
| CVE-2025-42947 | MEDIUM | 5.5 | 0.3% | Jul 23, 2025 | SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be execute... |
| CVE-2025-7722 | HIGH | 8.8 | 0.4% | Jul 23, 2025 | The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.... |
| CVE-2025-6261 | MEDIUM | 6.4 | 0.2% | Jul 23, 2025 | The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetw... |
| CVE-2025-6215 | MEDIUM | 5.3 | 0.3% | Jul 23, 2025 | The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and includ... |
| CVE-2025-6214 | MEDIUM | 6.5 | 0.2% | Jul 23, 2025 | The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all ver... |
| CVE-2025-6190 | HIGH | 8.8 | 0.4% | Jul 23, 2025 | The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now