2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8179 | CRITICAL | 9.8 | 0.5% | Jul 26, 2025 | A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affec... |
| CVE-2025-6895 | CRITICAL | 9.8 | 0.7% | Jul 26, 2025 | The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization wi... |
| CVE-2025-54416 | CRITICAL | 9.1 | 0.5% | Jul 26, 2025 | tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with supp... |
| CVE-2025-54415 | CRITICAL | 9.1 | 0.6% | Jul 26, 2025 | dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0... |
| CVE-2025-54385 | CRITICAL | 9.8 | 0.6% | Jul 26, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions bet... |
| CVE-2025-8173 | CRITICAL | 9.8 | 0.5% | Jul 25, 2025 | A vulnerability has been found in 1000 Projects ABC Courier Management System 1.0 and classified as critical. Affected b... |
| CVE-2025-8169 | CRITICAL | 9.8 | 1.5% | Jul 25, 2025 | A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function formSetWanPPTPca... |
| CVE-2025-8168 | CRITICAL | 9.8 | 1.5% | Jul 25, 2025 | A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function ... |
| CVE-2025-30135 | CRITICAL | 9.4 | 0.5% | Jul 25, 2025 | An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur.... |
| CVE-2025-8166 | CRITICAL | 9.8 | 0.5% | Jul 25, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a... |
| CVE-2025-46199 | CRITICAL | 9.8 | 0.8% | Jul 25, 2025 | Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafte... |
| CVE-2025-29631 | CRITICAL | 9.8 | 1.8% | Jul 25, 2025 | Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.1... |
| CVE-2025-29629 | CRITICAL | 9.1 | 0.5% | Jul 25, 2025 | Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.1... |
| CVE-2025-29628 | CRITICAL | 9.4 | 0.3% | Jul 25, 2025 | A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware befo... |
| CVE-2025-8159 | CRITICAL | 9.8 | 14.3% | Jul 25, 2025 | A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. This issue affects the function formLang... |
| CVE-2025-45777 | CRITICAL | 9.8 | 0.7% | Jul 25, 2025 | An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass au... |
| CVE-2025-8125 | CRITICAL | 9.8 | 0.4% | Jul 25, 2025 | A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some... |
| CVE-2025-54379 | CRITICAL | 9.8 | 0.8% | Jul 24, 2025 | LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev... |
| CVE-2025-54369 | CRITICAL | 9.3 | 0.4% | Jul 24, 2025 | Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML lo... |
| CVE-2025-32429 | CRITICAL | 9.8 | 85.4% | Jul 24, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4... |
| CVE-2025-7404 | CRITICAL | 9.8 | 2.7% | Jul 24, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web,... |
| CVE-2025-6260 | CRITICAL | 9.8 | 0.5% | Jul 24, 2025 | The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated atta... |
| CVE-2025-48732 | CRITICAL | 9.8 | 1.1% | Jul 24, 2025 | An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially c... |
| CVE-2025-41420 | CRITICAL | 9.6 | 1.1% | Jul 24, 2025 | A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4... |
| CVE-2025-36548 | CRITICAL | 9.6 | 1.0% | Jul 24, 2025 | A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of W... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now