2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51869 | HIGH | 7.5 | 0.4% | Jul 21, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive inform... |
| CVE-2025-51868 | HIGH | 7.5 | 0.4% | Jul 21, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive inf... |
| CVE-2025-7935 | HIGH | 8.8 | 0.4% | Jul 21, 2025 | A vulnerability, which was classified as critical, was found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf51... |
| CVE-2025-7934 | HIGH | 8.8 | 0.4% | Jul 21, 2025 | A vulnerability, which was classified as critical, has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b... |
| CVE-2025-51403 | MEDIUM | 6.5 | 1.5% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.... |
| CVE-2025-51401 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attacke... |
| CVE-2025-51400 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attac... |
| CVE-2025-51398 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows att... |
| CVE-2025-51397 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers... |
| CVE-2025-51396 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web sc... |
| CVE-2025-36106 | HIGH | 8.2 | 0.2% | Jul 21, 2025 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information comin... |
| CVE-2025-36062 | HIGH | 7.5 | 0.2% | Jul 21, 2025 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could be vulnerable to information exposure due to the use of u... |
| CVE-2025-36057 | MEDIUM | 4.6 | 0.2% | Jul 21, 2025 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authe... |
| CVE-2025-7962 | HIGH | 7.5 | 0.8% | Jul 21, 2025 | In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 cha... |
| CVE-2025-7933 | CRITICAL | 9.8 | 0.6% | Jul 21, 2025 | A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects... |
| CVE-2025-52575 | MEDIUM | 6.5 | 0.7% | Jul 21, 2025 | EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulner... |
| CVE-2025-44654 | CRITICAL | 9.8 | 1.1% | Jul 21, 2025 | In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead t... |
| CVE-2025-44652 | HIGH | 7.5 | 0.5% | Jul 21, 2025 | In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. Th... |
| CVE-2025-36846 | CRITICAL | 9.8 | 4.7% | Jul 21, 2025 | An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost ... |
| CVE-2025-36845 | HIGH | 8.6 | 1.6% | Jul 21, 2025 | An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side... |
| CVE-2025-36107 | HIGH | 7.5 | 0.2% | Jul 21, 2025 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due ... |
| CVE-2025-7932 | HIGH | 8.8 | 5.5% | Jul 21, 2025 | A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldb... |
| CVE-2025-7931 | HIGH | 7.3 | 0.5% | Jul 21, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i... |
| CVE-2025-7717 | HIGH | 7.5 | 0.4% | Jul 21, 2025 | Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: f... |
| CVE-2025-7716 | MEDIUM | 6.1 | 0.2% | Jul 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time S... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now