2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54442 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54440 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54438 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54120 | CRITICAL | 9.3 | 0.1% | Jul 23, 2025 | PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9,... |
| CVE-2025-8044 | CRITICAL | 9.8 | 0.4% | Jul 22, 2025 | Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-8043 | CRITICAL | 9.8 | 0.4% | Jul 22, 2025 | Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Fir... |
| CVE-2025-8038 | CRITICAL | 9.8 | 0.2% | Jul 22, 2025 | Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox ... |
| CVE-2025-8037 | CRITICAL | 9.1 | 0.2% | Jul 22, 2025 | Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set o... |
| CVE-2025-8031 | CRITICAL | 9.8 | 0.4% | Jul 22, 2025 | The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti... |
| CVE-2025-8028 | CRITICAL | 9.8 | 0.5% | Jul 22, 2025 | On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction... |
| CVE-2025-6523 | CRITICAL | 9.5 | 0.4% | Jul 22, 2025 | Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker t... |
| CVE-2025-34143 | CRITICAL | 9.3 | 29.6% | Jul 22, 2025 | An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login... |
| CVE-2025-4285 | CRITICAL | 10 | 0.3% | Jul 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Informati... |
| CVE-2025-6187 | CRITICAL | 9.8 | 0.7% | Jul 22, 2025 | The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_inf... |
| CVE-2025-7950 | CRITICAL | 9.8 | 0.5% | Jul 22, 2025 | A vulnerability was found in code-projects Public Chat Room 1.0. It has been rated as critical. Affected by this issue i... |
| CVE-2025-54127 | CRITICAL | 9.8 | 0.4% | Jul 21, 2025 | HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and be... |
| CVE-2025-54122 | CRITICAL | 10 | 0.8% | Jul 21, 2025 | Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulne... |
| CVE-2025-54071 | CRITICAL | 9.4 | 0.7% | Jul 21, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-52362 | CRITICAL | 9.1 | 0.5% | Jul 21, 2025 | Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and... |
| CVE-2025-7933 | CRITICAL | 9.8 | 0.6% | Jul 21, 2025 | A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects... |
| CVE-2025-44654 | CRITICAL | 9.8 | 1.1% | Jul 21, 2025 | In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead t... |
| CVE-2025-36846 | CRITICAL | 9.8 | 4.7% | Jul 21, 2025 | An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost ... |
| CVE-2025-7393 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This iss... |
| CVE-2025-7930 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by thi... |
| CVE-2025-7929 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now