2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53103 | MEDIUM | 5.8 | 0.1% | Jul 1, 2025 | JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test ... |
| CVE-2025-53100 | HIGH | 8.6 | 1.3% | Jul 1, 2025 | RestDB's Codehooks.io MCP Server is an MCP server on the Codehooks.io platform. Prior to version 0.2.2, the MCP server i... |
| CVE-2025-52294 | MEDIUM | 5.7 | 0.2% | Jul 1, 2025 | Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypa... |
| CVE-2025-45083 | MEDIUM | 6.1 | 0.1% | Jul 1, 2025 | Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental p... |
| CVE-2025-45081 | HIGH | 8.8 | 0.3% | Jul 1, 2025 | Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data. |
| CVE-2025-45080 | — | — | — | Jul 1, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2025-37099 | CRITICAL | 9.8 | 0.6% | Jul 1, 2025 | A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. |
| CVE-2025-34081 | HIGH | 7.5 | 0.6% | Jul 1, 2025 | The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may cont... |
| CVE-2025-34080 | MEDIUM | 6.1 | 1.1% | Jul 1, 2025 | The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functi... |
| CVE-2025-6297 | HIGH | 8.2 | 0.3% | Jul 1, 2025 | It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a... |
| CVE-2025-6963 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerabilit... |
| CVE-2025-6962 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects a... |
| CVE-2025-6961 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected ... |
| CVE-2025-50641 | MEDIUM | 6.5 | 0.4% | Jul 1, 2025 | Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId... |
| CVE-2025-6960 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability classified as critical was found in Campcodes Employee Management System 1.0. Affected by this vulnerabi... |
| CVE-2025-6959 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability classified as critical has been found in Campcodes Employee Management System 1.0. Affected is an unknow... |
| CVE-2025-6958 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0. It has been rated as critical. This issue affects... |
| CVE-2025-6957 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0. It has been declared as critical. This vulnerabil... |
| CVE-2025-53099 | HIGH | 7.5 | 0.7% | Jul 1, 2025 | Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a ... |
| CVE-2025-50405 | MEDIUM | 6.5 | 0.3% | Jul 1, 2025 | Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and ... |
| CVE-2025-50404 | MEDIUM | 5.3 | 6.3% | Jul 1, 2025 | Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly use... |
| CVE-2025-37098 | HIGH | 7.5 | 30.4% | Jul 1, 2025 | A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. |
| CVE-2025-34066 | HIGH | 8.3 | 0.3% | Jul 1, 2025 | An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with... |
| CVE-2025-34065 | MEDIUM | 6.9 | 0.5% | Jul 1, 2025 | An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr(... |
| CVE-2025-34064 | CRITICAL | 9 | 0.4% | Jul 1, 2025 | A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now