2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7918 | CRITICAL | 9.8 | 0.4% | Jul 21, 2025 | WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remot... |
| CVE-2025-7917 | HIGH | 8.6 | 0.5% | Jul 21, 2025 | WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attac... |
| CVE-2025-7916 | CRITICAL | 9.8 | 0.8% | Jul 21, 2025 | WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remot... |
| CVE-2025-54352 | LOW | 3.7 | 0.3% | Jul 21, 2025 | WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC... |
| CVE-2025-7915 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown function... |
| CVE-2025-7914 | HIGH | 8.8 | 0.8% | Jul 21, 2025 | A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is th... |
| CVE-2025-7913 | HIGH | 8.8 | 0.8% | Jul 21, 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the funct... |
| CVE-2025-7912 | HIGH | 8.8 | 1.0% | Jul 20, 2025 | A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affec... |
| CVE-2025-7911 | CRITICAL | 9.8 | 1.3% | Jul 20, 2025 | A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf ... |
| CVE-2025-53771 | MEDIUM | 6.5 | 99.9% | Jul 20, 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ... |
| CVE-2025-7910 | HIGH | 8.8 | 1.2% | Jul 20, 2025 | A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the f... |
| CVE-2025-7909 | HIGH | 8.8 | 1.2% | Jul 20, 2025 | A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. Affected by this issue is the function s... |
| CVE-2025-7908 | HIGH | 8.8 | 1.1% | Jul 20, 2025 | A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the... |
| CVE-2025-7907 | MEDIUM | 4.3 | 0.4% | Jul 20, 2025 | A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unkn... |
| CVE-2025-54319 | MEDIUM | 6.3 | 0.3% | Jul 20, 2025 | An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized acces... |
| CVE-2025-7906 | MEDIUM | 5.4 | 0.3% | Jul 20, 2025 | A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function... |
| CVE-2025-7905 | HIGH | 8.8 | 0.4% | Jul 20, 2025 | A vulnerability has been found in itsourcecode Insurance Management System 1.0 and classified as critical. This vulnerab... |
| CVE-2025-54317 | HIGH | 8.4 | 0.6% | Jul 20, 2025 | An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vuln... |
| CVE-2025-54316 | MEDIUM | 4.9 | 0.2% | Jul 20, 2025 | An issue was discovered in Logpoint before 7.6.0. When creating reports, attackers can create custom Jinja templates tha... |
| CVE-2025-49087 | LOW | 3.7 | 0.4% | Jul 20, 2025 | In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to... |
| CVE-2025-47917 | CRITICAL | 9.8 | 2.0% | Jul 20, 2025 | Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit... |
| CVE-2025-48965 | HIGH | 7.5 | 0.5% | Jul 20, 2025 | Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data ... |
| CVE-2025-7904 | HIGH | 8.8 | 0.4% | Jul 20, 2025 | A vulnerability, which was classified as critical, was found in itsourcecode Insurance Management System 1.0. This affec... |
| CVE-2025-7903 | MEDIUM | 5.4 | 0.2% | Jul 20, 2025 | A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability i... |
| CVE-2025-7902 | MEDIUM | 5.4 | 0.3% | Jul 20, 2025 | A vulnerability classified as problematic has been found in yangzongzhuan RuoYi up to 4.8.1. Affected is the function ad... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now