2025 CVE Vulnerabilities
45,262 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49809 | HIGH | 7.8 | 0.1% | Jul 4, 2025 | mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environm... |
| CVE-2025-48172 | MEDIUM | 5.6 | 0.2% | Jul 4, 2025 | CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow... |
| CVE-2025-38177 | MEDIUM | 5.5 | 0.2% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: make hfsc_qlen_notify() idempotent hfsc_... |
| CVE-2025-7066 | MEDIUM | 6.1 | 0.3% | Jul 4, 2025 | Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and HTML documents... |
| CVE-2025-6740 | MEDIUM | 6.1 | 0.3% | Jul 4, 2025 | The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tmpD’ param... |
| CVE-2025-6056 | MEDIUM | 6.9 | 0.3% | Jul 4, 2025 | Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows una... |
| CVE-2025-52833 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS l... |
| CVE-2025-52832 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart I... |
| CVE-2025-52831 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video... |
| CVE-2025-52830 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bSecure – Your Uni... |
| CVE-2025-52828 | HIGH | 8.8 | 0.3% | Jul 4, 2025 | Deserialization of Untrusted Data vulnerability in designthemes Red Art redart allows Object Injection.This issue affect... |
| CVE-2025-52813 | HIGH | 8.1 | 0.3% | Jul 4, 2025 | Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security ... |
| CVE-2025-52807 | HIGH | 8.1 | 0.4% | Jul 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52805 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | Path Traversal: '.../...//' vulnerability in VaultDweller Leyka leyka allows PHP Local File Inclusion.This issue affects... |
| CVE-2025-52798 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch w... |
| CVE-2025-52796 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tggfref WP-Recall ... |
| CVE-2025-52776 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video... |
| CVE-2025-52718 | HIGH | 7.2 | 0.2% | Jul 4, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code I... |
| CVE-2025-50039 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in vgwort VG WORT METIS vgw-metis allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-50032 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in Paytiko - Payment Orchestration Platform Paytiko for WooCommerce paytiko allows E... |
| CVE-2025-4414 | HIGH | 8.1 | 0.4% | Jul 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49870 | HIGH | 7.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Me... |
| CVE-2025-49867 | CRITICAL | 9.8 | 0.3% | Jul 4, 2025 | Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue... |
| CVE-2025-49866 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikel Beautiful Co... |
| CVE-2025-49431 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in Gnuget MF Plus WPML mf-plus-wpml allows Exploiting Incorrectly Configured Access ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now