2025 CVE Vulnerabilities
45,322 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41687 | CRITICAL | 9.8 | 0.7% | Jul 23, 2025 | An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full acces... |
| CVE-2025-8070 | CRITICAL | 9.2 | 0.2% | Jul 23, 2025 | The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allow... |
| CVE-2025-54455 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ... |
| CVE-2025-54454 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ... |
| CVE-2025-54453 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54452 | CRITICAL | 9.8 | 0.4% | Jul 23, 2025 | Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue ... |
| CVE-2025-54451 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows... |
| CVE-2025-54450 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54449 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54448 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54447 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54446 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54445 | CRITICAL | 9.8 | 9.2% | Jul 23, 2025 | Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Ser... |
| CVE-2025-54444 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54443 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54442 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54440 | CRITICAL | 9.8 | 0.5% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54438 | CRITICAL | 9.8 | 0.6% | Jul 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi... |
| CVE-2025-54120 | CRITICAL | 9.3 | 0.1% | Jul 23, 2025 | PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9,... |
| CVE-2025-8044 | CRITICAL | 9.8 | 0.4% | Jul 22, 2025 | Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-8043 | CRITICAL | 9.8 | 0.4% | Jul 22, 2025 | Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Fir... |
| CVE-2025-8038 | CRITICAL | 9.8 | 0.2% | Jul 22, 2025 | Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox ... |
| CVE-2025-8037 | CRITICAL | 9.1 | 0.2% | Jul 22, 2025 | Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set o... |
| CVE-2025-8031 | CRITICAL | 9.8 | 0.5% | Jul 22, 2025 | The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti... |
| CVE-2025-8028 | CRITICAL | 9.8 | 0.5% | Jul 22, 2025 | On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now