2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53840 | LOW | 2.4 | 0.3% | Jul 16, 2025 | Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2... |
| CVE-2025-40919 | MEDIUM | 6.5 | 0.3% | Jul 16, 2025 | Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is gene... |
| CVE-2025-40918 | MEDIUM | 6.5 | 0.4% | Jul 16, 2025 | Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (clien... |
| CVE-2025-40913 | MEDIUM | 6.5 | 0.3% | Jul 16, 2025 | Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net:... |
| CVE-2025-40776 | HIGH | 8.6 | 0.2% | Jul 16, 2025 | A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-pois... |
| CVE-2025-3871 | MEDIUM | 5.3 | 0.3% | Jul 16, 2025 | Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situati... |
| CVE-2025-40923 | HIGH | 7.3 | 0.3% | Jul 16, 2025 | Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generato... |
| CVE-2025-34300 | CRITICAL | 10 | 49.1% | Jul 16, 2025 | A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ci... |
| CVE-2025-53758 | MEDIUM | 5.1 | 0.1% | Jul 16, 2025 | This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management in... |
| CVE-2025-53757 | HIGH | 8.7 | 0.3% | Jul 16, 2025 | This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on ses... |
| CVE-2025-53756 | HIGH | 8.7 | 0.3% | Jul 16, 2025 | This vulnerability exists in Digisol DG-GR6821AC Router due to cleartext transmission of credentials in its web manageme... |
| CVE-2025-53755 | MEDIUM | 5.1 | 0.1% | Jul 16, 2025 | This vulnerability exists in Digisol DG-GR6821AC Router due to storage of credentials and PINS without encryption in the... |
| CVE-2025-53754 | MEDIUM | 5.1 | 0.2% | Jul 16, 2025 | This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials in system configuratio... |
| CVE-2025-52836 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Pr... |
| CVE-2025-52819 | HIGH | 8.5 | 0.3% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pakkemx Pakke Enví... |
| CVE-2025-52804 | HIGH | 7.5 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in uxper Nuss nuss allows Accessing Functionality Not Properly Constrained by ACLs.T... |
| CVE-2025-52803 | HIGH | 7.5 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in uxper Sala allows Accessing Functionality Not Properly Constrained by ACLs. This ... |
| CVE-2025-52787 | HIGH | 7.1 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EZiHosting Tennis ... |
| CVE-2025-52786 | HIGH | 7.1 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kingdom Creation M... |
| CVE-2025-52779 | HIGH | 7.1 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot ht... |
| CVE-2025-52777 | HIGH | 7.1 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmsMinds Pay with ... |
| CVE-2025-52714 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele... |
| CVE-2025-50028 | MEDIUM | 6.5 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifications allows Exploitin... |
| CVE-2025-49888 | HIGH | 7.1 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in pimwick PW WooCommerce On Sale! pw-woocommerce-on-sale allows Exploiting Incorrec... |
| CVE-2025-49884 | MEDIUM | 6.5 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in alexvtn Internal Linking of Related Contents internal-linking-of-related-contents... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now