2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49656 | HIGH | 7.5 | 1.4% | Jul 21, 2025 | Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affe... |
| CVE-2025-41681 | MEDIUM | 4.8 | 0.3% | Jul 21, 2025 | A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special el... |
| CVE-2025-41679 | HIGH | 7.5 | 0.6% | Jul 21, 2025 | An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of servi... |
| CVE-2025-41678 | HIGH | 7.2 | 0.6% | Jul 21, 2025 | A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization ... |
| CVE-2025-41677 | MEDIUM | 4.9 | 0.6% | Jul 21, 2025 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to... |
| CVE-2025-41676 | MEDIUM | 4.9 | 0.5% | Jul 21, 2025 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to... |
| CVE-2025-41675 | HIGH | 7.2 | 0.6% | Jul 21, 2025 | A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communicati... |
| CVE-2025-41674 | HIGH | 7.2 | 0.6% | Jul 21, 2025 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due t... |
| CVE-2025-41673 | HIGH | 7.2 | 0.6% | Jul 21, 2025 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to ... |
| CVE-2025-1469 | HIGH | 7.5 | 0.4% | Jul 21, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted ... |
| CVE-2025-7369 | MEDIUM | 6.1 | 0.2% | Jul 21, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v... |
| CVE-2025-7354 | MEDIUM | 6.4 | 0.3% | Jul 21, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-4685 | MEDIUM | 6.4 | 0.2% | Jul 21, 2025 | The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-4570 | MEDIUM | 6.9 | 0.4% | Jul 21, 2025 | An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token t... |
| CVE-2025-4569 | HIGH | 7.7 | 0.4% | Jul 21, 2025 | An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token t... |
| CVE-2025-4049 | HIGH | 8.6 | 0.2% | Jul 21, 2025 | Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allow... |
| CVE-2025-7921 | CRITICAL | 9.8 | 0.8% | Jul 21, 2025 | Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote... |
| CVE-2025-7920 | MEDIUM | 6.1 | 0.3% | Jul 21, 2025 | WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unau... |
| CVE-2025-7919 | HIGH | 7.1 | 0.4% | Jul 21, 2025 | WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remot... |
| CVE-2025-7344 | HIGH | 8.8 | 0.5% | Jul 21, 2025 | The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges... |
| CVE-2025-7343 | CRITICAL | 9.8 | 0.6% | Jul 21, 2025 | The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbi... |
| CVE-2025-24938 | HIGH | 8.4 | 0.3% | Jul 21, 2025 | The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An at... |
| CVE-2025-24937 | CRITICAL | 9 | 0.2% | Jul 21, 2025 | File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in... |
| CVE-2025-24936 | CRITICAL | 9 | 0.3% | Jul 21, 2025 | The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The v... |
| CVE-2025-0664 | MEDIUM | 6.7 | 0.2% | Jul 21, 2025 | A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now