2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54424 | CRITICAL | 9.8 | 0.9% | Aug 1, 2025 | 1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server... |
| CVE-2025-6000 | CRITICAL | 9.1 | 0.9% | Aug 1, 2025 | A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution o... |
| CVE-2025-54574 | CRITICAL | 9.8 | 23.5% | Aug 1, 2025 | Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possi... |
| CVE-2025-50870 | CRITICAL | 9.8 | 0.3% | Aug 1, 2025 | Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The my... |
| CVE-2025-45150 | CRITICAL | 9.8 | 0.6% | Aug 1, 2025 | Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive... |
| CVE-2025-52390 | CRITICAL | 9.1 | 0.5% | Aug 1, 2025 | Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `p... |
| CVE-2025-50472 | CRITICAL | 9.8 | 1.2% | Aug 1, 2025 | The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untruste... |
| CVE-2025-50460 | CRITICAL | 9.8 | 2.3% | Aug 1, 2025 | A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization i... |
| CVE-2025-41375 | CRITICAL | 9.8 | 0.6% | Aug 1, 2025 | SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, upd... |
| CVE-2025-8443 | CRITICAL | 9.8 | 0.5% | Aug 1, 2025 | A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue ... |
| CVE-2025-8442 | CRITICAL | 9.8 | 0.5% | Aug 1, 2025 | A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this v... |
| CVE-2025-8441 | CRITICAL | 9.8 | 0.5% | Aug 1, 2025 | A vulnerability, which was classified as critical, was found in code-projects Online Medicine Guide 1.0. Affected is an ... |
| CVE-2025-8439 | CRITICAL | 9.8 | 0.5% | Aug 1, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Wazifa System 1.0. This issue affects... |
| CVE-2025-8438 | CRITICAL | 9.8 | 0.5% | Aug 1, 2025 | A vulnerability classified as critical was found in code-projects Wazifa System 1.0. This vulnerability affects unknown ... |
| CVE-2025-8437 | CRITICAL | 9.8 | 0.5% | Aug 1, 2025 | A vulnerability classified as critical has been found in code-projects Kitchen Treasure 1.0. This affects an unknown par... |
| CVE-2025-8454 | CRITICAL | 9.8 | 0.2% | Aug 1, 2025 | It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts... |
| CVE-2025-8436 | CRITICAL | 9.8 | 0.4% | Aug 1, 2025 | A vulnerability was found in projectworlds Online Admission System 1.0. It has been rated as critical. Affected by this ... |
| CVE-2025-5947 | CRITICAL | 9.8 | 5.7% | Aug 1, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all ... |
| CVE-2025-5954 | CRITICAL | 9.8 | 0.4% | Aug 1, 2025 | The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all ver... |
| CVE-2025-8431 | CRITICAL | 9.8 | 0.5% | Aug 1, 2025 | A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe... |
| CVE-2025-48072 | CRITICAL | 9.1 | 0.5% | Jul 31, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-8286 | CRITICAL | 9.3 | 1.2% | Jul 31, 2025 | The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modi... |
| CVE-2025-26063 | CRITICAL | 9.8 | 1.2% | Jul 31, 2025 | An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via in... |
| CVE-2025-26062 | CRITICAL | 9.8 | 1.0% | Jul 31, 2025 | An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the rou... |
| CVE-2025-8426 | CRITICAL | 9.4 | 1.6% | Jul 31, 2025 | Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerabil... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now