2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51864 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, all... |
| CVE-2025-51863 | MEDIUM | 6.1 | 0.3% | Jul 22, 2025 | Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to exec... |
| CVE-2025-51862 | MEDIUM | 6.1 | 0.2% | Jul 22, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in TelegAI (telegai.com) thru 2025-05-26 in its chat component. An... |
| CVE-2025-51860 | MEDIUM | 6.1 | 0.3% | Jul 22, 2025 | Stored Cross-Site Scripting (XSS) in TelegAI (telegai.com) 2025-05-26 in its chat component and character container comp... |
| CVE-2025-51859 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Chaindesk thru 2025-05-26 in its agent chat component. An attacker ca... |
| CVE-2025-51858 | MEDIUM | 6.1 | 0.3% | Jul 22, 2025 | Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbit... |
| CVE-2025-4878 | LOW | 3.6 | 0.2% | Jul 22, 2025 | A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_f... |
| CVE-2025-8017 | HIGH | 8.8 | 8.3% | Jul 22, 2025 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSet... |
| CVE-2025-51867 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing att... |
| CVE-2025-4295 | MEDIUM | 4.6 | 0.1% | Jul 22, 2025 | Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting. ... |
| CVE-2025-4294 | MEDIUM | 4.8 | 0.2% | Jul 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HotelRunner... |
| CVE-2025-34143 | CRITICAL | 9.3 | 29.6% | Jul 22, 2025 | An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login... |
| CVE-2025-34142 | MEDIUM | 6.9 | 0.9% | Jul 22, 2025 | An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/res... |
| CVE-2025-34141 | MEDIUM | 5.1 | 1.9% | Jul 22, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverte... |
| CVE-2025-34140 | HIGH | 8.7 | 0.6% | Jul 22, 2025 | An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific... |
| CVE-2025-7705 | HIGH | 8.6 | 0.2% | Jul 22, 2025 | : Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.Thi... |
| CVE-2025-4285 | CRITICAL | 10 | 0.3% | Jul 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Informati... |
| CVE-2025-4284 | MEDIUM | 6.1 | 0.2% | Jul 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rolantis In... |
| CVE-2025-7900 | MEDIUM | 6.5 | 0.2% | Jul 22, 2025 | The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of user... |
| CVE-2025-7899 | MEDIUM | 6 | 0.3% | Jul 22, 2025 | The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from ... |
| CVE-2025-7692 | HIGH | 8.1 | 0.5% | Jul 22, 2025 | The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includin... |
| CVE-2025-7687 | MEDIUM | 6.1 | 0.1% | Jul 22, 2025 | The Latest Post Accordian Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-7685 | MEDIUM | 6.1 | 0.1% | Jul 22, 2025 | The Like & Share My Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-7427 | MEDIUM | 5.9 | 0.2% | Jul 22, 2025 | Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking ... |
| CVE-2025-6213 | HIGH | 7.2 | 0.7% | Jul 22, 2025 | The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now