2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44658 | CRITICAL | 9.8 | 1.0% | Jul 21, 2025 | In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to on... |
| CVE-2025-44655 | CRITICAL | 9.8 | 0.3% | Jul 21, 2025 | In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This co... |
| CVE-2025-7928 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical. This issue affects som... |
| CVE-2025-46122 | CRITICAL | 9.1 | 1.1% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticat... |
| CVE-2025-46121 | CRITICAL | 9.8 | 1.2% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `... |
| CVE-2025-46120 | CRITICAL | 9.8 | 1.0% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDir... |
| CVE-2025-46117 | CRITICAL | 9.1 | 0.8% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir... |
| CVE-2025-7624 | CRITICAL | 9.8 | 7.2% | Jul 21, 2025 | An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (2... |
| CVE-2025-6704 | CRITICAL | 9.8 | 8.2% | Jul 21, 2025 | An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than ... |
| CVE-2025-7921 | CRITICAL | 9.8 | 0.8% | Jul 21, 2025 | Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote... |
| CVE-2025-7343 | CRITICAL | 9.8 | 0.6% | Jul 21, 2025 | The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbi... |
| CVE-2025-24937 | CRITICAL | 9 | 0.2% | Jul 21, 2025 | File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in... |
| CVE-2025-24936 | CRITICAL | 9 | 0.3% | Jul 21, 2025 | The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The v... |
| CVE-2025-7918 | CRITICAL | 9.8 | 0.4% | Jul 21, 2025 | WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remot... |
| CVE-2025-7916 | CRITICAL | 9.8 | 0.8% | Jul 21, 2025 | WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remot... |
| CVE-2025-7915 | CRITICAL | 9.8 | 0.5% | Jul 21, 2025 | A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown function... |
| CVE-2025-7911 | CRITICAL | 9.8 | 1.3% | Jul 20, 2025 | A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf ... |
| CVE-2025-47917 | CRITICAL | 9.8 | 2.0% | Jul 20, 2025 | Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit... |
| CVE-2025-7897 | CRITICAL | 9.8 | 0.6% | Jul 20, 2025 | A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue ... |
| CVE-2025-7895 | CRITICAL | 9.8 | 0.4% | Jul 20, 2025 | A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the... |
| CVE-2025-7894 | CRITICAL | 9.8 | 0.5% | Jul 20, 2025 | A vulnerability, which was classified as critical, has been found in Onyx up to 0.29.1. This issue affects the function ... |
| CVE-2025-7888 | CRITICAL | 9.8 | 0.5% | Jul 20, 2025 | A vulnerability was found in TDuckCloud tduck-platform 5.1 and classified as critical. This issue affects the function U... |
| CVE-2025-7879 | CRITICAL | 9.8 | 0.5% | Jul 20, 2025 | A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnera... |
| CVE-2025-7877 | CRITICAL | 9.8 | 0.5% | Jul 20, 2025 | A vulnerability, which was classified as critical, has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This issue affec... |
| CVE-2025-7876 | CRITICAL | 9.8 | 0.7% | Jul 20, 2025 | A vulnerability classified as critical was found in Metasoft 美特软件 MetaCRM up to 6.4.2. This vulnerability affects the fu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now