2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7874 | CRITICAL | 9.1 | 0.7% | Jul 20, 2025 | A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue... |
| CVE-2025-7873 | CRITICAL | 9.8 | 0.4% | Jul 20, 2025 | A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been declared as critical. Affected by this vulne... |
| CVE-2025-7862 | CRITICAL | 9.8 | 1.0% | Jul 20, 2025 | A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnera... |
| CVE-2025-7861 | CRITICAL | 9.8 | 0.4% | Jul 20, 2025 | A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an... |
| CVE-2025-7860 | CRITICAL | 9.8 | 0.4% | Jul 20, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issu... |
| CVE-2025-7859 | CRITICAL | 9.8 | 0.4% | Jul 20, 2025 | A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects... |
| CVE-2025-53770 | CRITICAL | 9.8 | 100.0% | Jul 20, 2025 | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute ... |
| CVE-2025-7838 | CRITICAL | 9.8 | 0.6% | Jul 19, 2025 | A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1.0 and classified as critical.... |
| CVE-2025-7833 | CRITICAL | 9.8 | 0.4% | Jul 19, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issu... |
| CVE-2025-7832 | CRITICAL | 9.8 | 0.4% | Jul 19, 2025 | A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects... |
| CVE-2025-7831 | CRITICAL | 9.8 | 0.4% | Jul 19, 2025 | A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unkno... |
| CVE-2025-7830 | CRITICAL | 9.8 | 0.4% | Jul 19, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i... |
| CVE-2025-7829 | CRITICAL | 9.8 | 0.4% | Jul 19, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by thi... |
| CVE-2025-7824 | CRITICAL | 9.8 | 0.5% | Jul 19, 2025 | A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing... |
| CVE-2025-7823 | CRITICAL | 9.8 | 0.5% | Jul 19, 2025 | A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code... |
| CVE-2025-29757 | CRITICAL | 9.4 | 0.4% | Jul 19, 2025 | An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous at... |
| CVE-2025-7697 | CRITICAL | 9.8 | 1.1% | Jul 19, 2025 | The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable... |
| CVE-2025-7696 | CRITICAL | 9.8 | 1.0% | Jul 19, 2025 | The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to ... |
| CVE-2025-7395 | CRITICAL | 9.2 | 0.2% | Jul 18, 2025 | A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VA... |
| CVE-2025-7394 | CRITICAL | 9.8 | 0.4% | Jul 18, 2025 | In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to ... |
| CVE-2025-7814 | CRITICAL | 9.8 | 0.4% | Jul 18, 2025 | A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability af... |
| CVE-2025-54309 | CRITICAL | 9.8 | 92.0% | Jul 18, 2025 | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and... |
| CVE-2025-7783 | CRITICAL | 9.4 | 1.7% | Jul 18, 2025 | Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability... |
| CVE-2025-53762 | CRITICAL | 9.9 | 0.7% | Jul 18, 2025 | Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a networ... |
| CVE-2025-47158 | CRITICAL | 9 | 0.7% | Jul 18, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now