2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40600 | CRITICAL | 9.8 | 0.8% | Jul 29, 2025 | Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticate... |
| CVE-2025-53102 | CRITICAL | 9.8 | 0.4% | Jul 29, 2025 | Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5... |
| CVE-2025-44136 | CRITICAL | 9.8 | 2.4% | Jul 29, 2025 | MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e... |
| CVE-2025-50738 | CRITICAL | 9.8 | 2.0% | Jul 29, 2025 | The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us... |
| CVE-2025-46059 | CRITICAL | 9.8 | 0.7% | Jul 29, 2025 | langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component.... |
| CVE-2025-7458 | CRITICAL | 9.1 | 0.2% | Jul 29, 2025 | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attack... |
| CVE-2025-40682 | CRITICAL | 9.8 | 0.3% | Jul 29, 2025 | SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, creat... |
| CVE-2025-53082 | CRITICAL | 9.1 | 0.4% | Jul 29, 2025 | An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unin... |
| CVE-2025-53081 | CRITICAL | 9.1 | 0.4% | Jul 29, 2025 | An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in uninte... |
| CVE-2025-8264 | CRITICAL | 9 | 0.4% | Jul 29, 2025 | Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in... |
| CVE-2025-53078 | CRITICAL | 9.8 | 0.4% | Jul 29, 2025 | Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via ... |
| CVE-2025-54428 | CRITICAL | 9.8 | 0.5% | Jul 28, 2025 | RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessibl... |
| CVE-2025-54426 | CRITICAL | 9.9 | 0.3% | Jul 28, 2025 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f... |
| CVE-2025-54419 | CRITICAL | 10 | 0.4% | Jul 28, 2025 | A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from t... |
| CVE-2025-54299 | CRITICAL | 9.4 | 0.4% | Jul 28, 2025 | A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered. |
| CVE-2025-54298 | CRITICAL | 9.4 | 0.4% | Jul 28, 2025 | A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered. |
| CVE-2025-43023 | CRITICAL | 9.1 | 0.2% | Jul 28, 2025 | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This... |
| CVE-2025-54531 | CRITICAL | 9.4 | 0.3% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows |
| CVE-2025-54530 | CRITICAL | 9.8 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions |
| CVE-2025-54418 | CRITICAL | 9.8 | 1.5% | Jul 28, 2025 | CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affe... |
| CVE-2025-53696 | CRITICAL | 9.3 | 0.1% | Jul 28, 2025 | iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the ... |
| CVE-2025-30125 | CRITICAL | 9.8 | 0.4% | Jul 28, 2025 | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default crede... |
| CVE-2025-8279 | CRITICAL | 9.8 | 0.4% | Jul 28, 2025 | Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query... |
| CVE-2025-53695 | CRITICAL | 9.4 | 0.9% | Jul 28, 2025 | OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileg... |
| CVE-2025-30133 | CRITICAL | 9.8 | 0.5% | Jul 28, 2025 | An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires devic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now