2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50584 | MEDIUM | 4.8 | 0.2% | Jul 18, 2025 | StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module... |
| CVE-2025-7802 | MEDIUM | 5.4 | 0.2% | Jul 18, 2025 | A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as problematic. Affected by this ... |
| CVE-2025-7801 | HIGH | 7.3 | 0.3% | Jul 18, 2025 | A vulnerability has been found in BossSoft CRM 6.0 and classified as critical. Affected by this vulnerability is an unkn... |
| CVE-2025-7800 | MEDIUM | 5.1 | 0.2% | Jul 18, 2025 | A vulnerability classified as problematic was found in cgpandey hotelmis up to c572198e6c4780fccc63b1d3e8f3f72f825fc94e.... |
| CVE-2025-7798 | MEDIUM | 6.3 | 0.2% | Jul 18, 2025 | A vulnerability classified as critical has been found in Beijing Shenzhou Shihan Technology Multimedia Integrated Busine... |
| CVE-2025-54309 | CRITICAL | 9.8 | 92.0% | Jul 18, 2025 | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and... |
| CVE-2025-52169 | HIGH | 7.1 | 0.2% | Jul 18, 2025 | agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS... |
| CVE-2025-52163 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v... |
| CVE-2025-50585 | HIGH | 8.8 | 0.4% | Jul 18, 2025 | StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl. |
| CVE-2025-33014 | MEDIUM | 6.1 | 0.2% | Jul 18, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web... |
| CVE-2025-7797 | MEDIUM | 5.5 | 0.9% | Jul 18, 2025 | A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf... |
| CVE-2025-7796 | HIGH | 8.8 | 0.8% | Jul 18, 2025 | A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpU... |
| CVE-2025-7795 | HIGH | 8.8 | 2.8% | Jul 18, 2025 | A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the ... |
| CVE-2025-53901 | LOW | 3.5 | 0.3% | Jul 18, 2025 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation ... |
| CVE-2025-52168 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 all... |
| CVE-2025-52166 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate... |
| CVE-2025-52164 | HIGH | 8.2 | 0.2% | Jul 18, 2025 | Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext. |
| CVE-2025-7794 | HIGH | 8.8 | 1.0% | Jul 18, 2025 | A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function ... |
| CVE-2025-7793 | HIGH | 8.8 | 1.0% | Jul 18, 2025 | A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function formWebTypeLibrar... |
| CVE-2025-7792 | HIGH | 8.8 | 1.0% | Jul 18, 2025 | A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function formSaf... |
| CVE-2025-7783 | CRITICAL | 9.4 | 1.7% | Jul 18, 2025 | Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability... |
| CVE-2025-53762 | CRITICAL | 9.9 | 0.7% | Jul 18, 2025 | Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a networ... |
| CVE-2025-52162 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the ... |
| CVE-2025-50586 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF). |
| CVE-2025-49747 | HIGH | 8.8 | 0.6% | Jul 18, 2025 | Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now