2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54060 | HIGH | 8.8 | 0.5% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-54058 | HIGH | 8.8 | 0.5% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-47189 | MEDIUM | 6.1 | 0.2% | Jul 17, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d... |
| CVE-2025-53946 | HIGH | 8.8 | 0.4% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-53941 | MEDIUM | 6.1 | 0.2% | Jul 17, 2025 | Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to ... |
| CVE-2025-53928 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution ... |
| CVE-2025-53927 | MEDIUM | 6.3 | 0.2% | Jul 17, 2025 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed be... |
| CVE-2025-53909 | HIGH | 7.2 | 0.5% | Jul 17, 2025 | mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vul... |
| CVE-2025-51630 | CRITICAL | 9.8 | 0.5% | Jul 17, 2025 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the functi... |
| CVE-2025-40924 | MEDIUM | 6.5 | 0.3% | Jul 17, 2025 | Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated fr... |
| CVE-2025-1713 | HIGH | 7.5 | 0.7% | Jul 17, 2025 | When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream brid... |
| CVE-2025-5346 | MEDIUM | 5.1 | 0.1% | Jul 17, 2025 | Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast recei... |
| CVE-2025-5345 | MEDIUM | 6.3 | 0.1% | Jul 17, 2025 | Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "... |
| CVE-2025-5344 | HIGH | 8.5 | 0.1% | Jul 17, 2025 | Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.blu... |
| CVE-2025-52933 | — | — | — | Jul 17, 2025 | Rejected reason: 3rd party vulnerability |
| CVE-2025-3415 | MEDIUM | 4.3 | 0.9% | Jul 17, 2025 | Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p... |
| CVE-2025-4302 | MEDIUM | 5.3 | 0.8% | Jul 17, 2025 | The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-a... |
| CVE-2025-7735 | HIGH | 8.7 | 0.4% | Jul 17, 2025 | The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote a... |
| CVE-2025-7712 | CRITICAL | 9.1 | 0.8% | Jul 17, 2025 | The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation... |
| CVE-2025-7729 | MEDIUM | 5.4 | 0.3% | Jul 17, 2025 | A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unk... |
| CVE-2025-7728 | MEDIUM | 5.4 | 0.3% | Jul 17, 2025 | A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of ... |
| CVE-2025-5396 | CRITICAL | 9.8 | 0.7% | Jul 17, 2025 | The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0... |
| CVE-2025-34132 | CRITICAL | 9.3 | 1.8% | Jul 16, 2025 | A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_... |
| CVE-2025-34130 | HIGH | 8.7 | 1.1% | Jul 16, 2025 | An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.... |
| CVE-2025-34129 | HIGH | 8.7 | 1.1% | Jul 16, 2025 | A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now