2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6523 | CRITICAL | 9.5 | 0.4% | Jul 22, 2025 | Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker t... |
| CVE-2025-34143 | CRITICAL | 9.3 | 29.6% | Jul 22, 2025 | An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login... |
| CVE-2025-4285 | CRITICAL | 10 | 0.3% | Jul 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Informati... |
| CVE-2025-6187 | CRITICAL | 9.8 | 0.7% | Jul 22, 2025 | The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_inf... |
| CVE-2025-7950 | CRITICAL | 9.8 | 0.5% | Jul 22, 2025 | A vulnerability was found in code-projects Public Chat Room 1.0. It has been rated as critical. Affected by this issue i... |
| CVE-2025-54127 | CRITICAL | 9.8 | 0.4% | Jul 21, 2025 | HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and be... |
| CVE-2025-54122 | CRITICAL | 10 | 0.8% | Jul 21, 2025 | Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulne... |
| CVE-2025-54071 | CRITICAL | 9.4 | 0.7% | Jul 21, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-52362 | CRITICAL | 9.1 | 0.5% | Jul 21, 2025 | Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and... |
| CVE-2025-7933 | CRITICAL | 9.8 | 0.6% | Jul 21, 2025 | A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects... |
| CVE-2025-44654 | CRITICAL | 9.8 | 1.1% | Jul 21, 2025 | In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead t... |
| CVE-2025-36846 | CRITICAL | 9.8 | 4.7% | Jul 21, 2025 | An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost ... |
| CVE-2025-7393 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This iss... |
| CVE-2025-7930 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by thi... |
| CVE-2025-7929 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a... |
| CVE-2025-44658 | CRITICAL | 9.8 | 1.0% | Jul 21, 2025 | In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to on... |
| CVE-2025-44655 | CRITICAL | 9.8 | 0.3% | Jul 21, 2025 | In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This co... |
| CVE-2025-7928 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical. This issue affects som... |
| CVE-2025-46122 | CRITICAL | 9.1 | 1.1% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticat... |
| CVE-2025-46121 | CRITICAL | 9.8 | 1.2% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `... |
| CVE-2025-46120 | CRITICAL | 9.8 | 1.0% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDir... |
| CVE-2025-46117 | CRITICAL | 9.1 | 0.8% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir... |
| CVE-2025-7624 | CRITICAL | 9.8 | 7.2% | Jul 21, 2025 | An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (2... |
| CVE-2025-6704 | CRITICAL | 9.8 | 8.2% | Jul 21, 2025 | An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than ... |
| CVE-2025-7921 | CRITICAL | 9.8 | 0.8% | Jul 21, 2025 | Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now