2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4784 | CRITICAL | 9.8 | 0.5% | Jul 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella ... |
| CVE-2025-5243 | CRITICAL | 10 | 1.5% | Jul 24, 2025 | Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS ... |
| CVE-2025-4822 | CRITICAL | 9.8 | 0.7% | Jul 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar En... |
| CVE-2025-6441 | CRITICAL | 9.8 | 1.0% | Jul 24, 2025 | The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin ... |
| CVE-2025-6380 | CRITICAL | 9.8 | 0.7% | Jul 24, 2025 | The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o... |
| CVE-2025-7852 | CRITICAL | 9.8 | 1.2% | Jul 24, 2025 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima... |
| CVE-2025-7437 | CRITICAL | 9.8 | 1.3% | Jul 24, 2025 | The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ... |
| CVE-2025-41240 | CRITICAL | 10 | 0.7% | Jul 24, 2025 | Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located wit... |
| CVE-2025-40599 | CRITICAL | 9.1 | 11.6% | Jul 23, 2025 | An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote att... |
| CVE-2025-54294 | CRITICAL | 9.3 | 0.3% | Jul 23, 2025 | A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to e... |
| CVE-2025-41687 | CRITICAL | 9.8 | 0.7% | Jul 23, 2025 | An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full acces... |
| CVE-2025-8070 | CRITICAL | 9.2 | 0.2% | Jul 23, 2025 | The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allow... |
| CVE-2025-54455 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ... |
| CVE-2025-54454 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ... |
| CVE-2025-54453 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54452 | CRITICAL | 9.8 | 0.4% | Jul 23, 2025 | Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue ... |
| CVE-2025-54451 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows... |
| CVE-2025-54450 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54449 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54448 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54447 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54446 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54445 | CRITICAL | 9.8 | 9.2% | Jul 23, 2025 | Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Ser... |
| CVE-2025-54444 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54443 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now