2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53888 | CRITICAL | 9.8 | 0.7% | Jul 18, 2025 | RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `a... |
| CVE-2025-46001 | CRITICAL | 9.8 | 0.6% | Jul 18, 2025 | An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to ... |
| CVE-2025-7444 | CRITICAL | 9.8 | 0.5% | Jul 18, 2025 | The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0... |
| CVE-2025-26855 | CRITICAL | 9.8 | 0.4% | Jul 18, 2025 | A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL c... |
| CVE-2025-26854 | CRITICAL | 9.8 | 0.4% | Jul 18, 2025 | A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQ... |
| CVE-2025-7643 | CRITICAL | 9.1 | 0.7% | Jul 18, 2025 | The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid... |
| CVE-2025-6222 | CRITICAL | 9.8 | 0.6% | Jul 18, 2025 | The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPres... |
| CVE-2025-6185 | CRITICAL | 9.3 | 0.3% | Jul 18, 2025 | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an atta... |
| CVE-2025-7765 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by thi... |
| CVE-2025-7764 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected i... |
| CVE-2025-7398 | CRITICAL | 9.1 | 0.2% | Jul 17, 2025 | Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and... |
| CVE-2025-6391 | CRITICAL | 9.1 | 0.2% | Jul 17, 2025 | Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withd... |
| CVE-2025-7757 | CRITICAL | 9.8 | 0.5% | Jul 17, 2025 | A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is... |
| CVE-2025-7753 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been classified as critical. Th... |
| CVE-2025-7752 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability was found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by... |
| CVE-2025-7751 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affect... |
| CVE-2025-53964 | CRITICAL | 9.6 | 0.4% | Jul 17, 2025 | GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a cr... |
| CVE-2025-23266 | CRITICAL | 9 | 2.5% | Jul 17, 2025 | NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher... |
| CVE-2025-7750 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Aff... |
| CVE-2025-54068 | CRITICAL | 9.8 | 95.4% | Jul 17, 2025 | Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauth... |
| CVE-2025-50240 | CRITICAL | 9.8 | 0.3% | Jul 17, 2025 | nbcio-boot v1.0.3 was discovered to contain a SQL injection vulnerability via the userIds parameter at /sys/user/deleteR... |
| CVE-2025-7749 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0... |
| CVE-2025-53644 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on s... |
| CVE-2025-53867 | CRITICAL | 9.8 | 0.7% | Jul 17, 2025 | Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL. |
| CVE-2025-52046 | CRITICAL | 9.8 | 5.2% | Jul 17, 2025 | Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 functio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now