2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34063 | CRITICAL | 10 | 0.5% | Jul 1, 2025 | A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure o... |
| CVE-2025-34062 | MEDIUM | 5.7 | 0.1% | Jul 1, 2025 | An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/conf... |
| CVE-2025-34060 | CRITICAL | 10 | 0.7% | Jul 1, 2025 | A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handli... |
| CVE-2025-34059 | HIGH | 8.7 | 0.4% | Jul 1, 2025 | An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username... |
| CVE-2025-34058 | HIGH | 8.7 | 0.9% | Jul 1, 2025 | Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate ... |
| CVE-2025-34056 | CRITICAL | 9.4 | 1.8% | Jul 1, 2025 | An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, whic... |
| CVE-2025-34055 | CRITICAL | 9.4 | 1.5% | Jul 1, 2025 | An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint... |
| CVE-2025-34054 | CRITICAL | 10 | 2.7% | Jul 1, 2025 | An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use... |
| CVE-2025-34053 | MEDIUM | 6.9 | 0.5% | Jul 1, 2025 | An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr(... |
| CVE-2025-34052 | — | — | — | Jul 1, 2025 | Rejected reason: An unauthenticated endpoint that exposes firmware version, MAC address, and supported codecs is not ind... |
| CVE-2025-34051 | MEDIUM | 6.9 | 0.5% | Jul 1, 2025 | A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the ... |
| CVE-2025-34050 | MEDIUM | 5.1 | 0.2% | Jul 1, 2025 | A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices.... |
| CVE-2025-6956 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects ... |
| CVE-2025-6955 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue... |
| CVE-2025-6954 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this ... |
| CVE-2025-6953 | HIGH | 8.8 | 0.8% | Jul 1, 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an un... |
| CVE-2025-6920 | MEDIUM | 5.3 | 0.3% | Jul 1, 2025 | A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* ... |
| CVE-2025-49029 | CRITICAL | 9.1 | 2.1% | Jul 1, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget cus... |
| CVE-2025-45872 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter. |
| CVE-2025-37097 | HIGH | 7.5 | 0.4% | Jul 1, 2025 | A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service |
| CVE-2025-36582 | HIGH | 7.5 | 0.2% | Jul 1, 2025 | Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorit... |
| CVE-2025-6952 | MEDIUM | 4.8 | 0.2% | Jul 1, 2025 | A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the func... |
| CVE-2025-6951 | MEDIUM | 4.3 | 0.2% | Jul 1, 2025 | A vulnerability classified as problematic was found in SAFECAM X300 up to 20250611. This vulnerability affects unknown c... |
| CVE-2025-5314 | MEDIUM | 6.1 | 0.3% | Jul 1, 2025 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to DOM-Based Ref... |
| CVE-2025-49483 | MEDIUM | 5.4 | 0.2% | Jul 1, 2025 | Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now