2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7398 | CRITICAL | 9.1 | 0.2% | Jul 17, 2025 | Brocade ASCG before 3.3.0 allows for the use of medium strength cryptography algorithms on internal ports ports 9000 and... |
| CVE-2025-6391 | CRITICAL | 9.1 | 0.2% | Jul 17, 2025 | Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withd... |
| CVE-2025-7757 | CRITICAL | 9.8 | 0.5% | Jul 17, 2025 | A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is... |
| CVE-2025-7753 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been classified as critical. Th... |
| CVE-2025-7752 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability was found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by... |
| CVE-2025-7751 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affect... |
| CVE-2025-53964 | CRITICAL | 9.6 | 0.4% | Jul 17, 2025 | GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a cr... |
| CVE-2025-23266 | CRITICAL | 9 | 2.5% | Jul 17, 2025 | NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher... |
| CVE-2025-7750 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Aff... |
| CVE-2025-54068 | CRITICAL | 9.8 | 95.4% | Jul 17, 2025 | Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauth... |
| CVE-2025-50240 | CRITICAL | 9.8 | 0.3% | Jul 17, 2025 | nbcio-boot v1.0.3 was discovered to contain a SQL injection vulnerability via the userIds parameter at /sys/user/deleteR... |
| CVE-2025-7749 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0... |
| CVE-2025-53644 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on s... |
| CVE-2025-53867 | CRITICAL | 9.8 | 0.7% | Jul 17, 2025 | Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL. |
| CVE-2025-52046 | CRITICAL | 9.8 | 5.2% | Jul 17, 2025 | Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 functio... |
| CVE-2025-25257 | CRITICAL | 9.8 | 96.7% | Jul 17, 2025 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi... |
| CVE-2025-53928 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution ... |
| CVE-2025-51630 | CRITICAL | 9.8 | 0.5% | Jul 17, 2025 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the functi... |
| CVE-2025-7712 | CRITICAL | 9.1 | 0.8% | Jul 17, 2025 | The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation... |
| CVE-2025-5396 | CRITICAL | 9.8 | 0.7% | Jul 17, 2025 | The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0... |
| CVE-2025-34132 | CRITICAL | 9.3 | 1.8% | Jul 16, 2025 | A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_... |
| CVE-2025-34127 | CRITICAL | 9.3 | 1.1% | Jul 16, 2025 | A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted messag... |
| CVE-2025-34125 | CRITICAL | 9.3 | 3.1% | Jul 16, 2025 | An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D... |
| CVE-2025-34121 | CRITICAL | 9.3 | 1.7% | Jul 16, 2025 | An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and inc... |
| CVE-2025-34117 | CRITICAL | 9.3 | 22.9% | Jul 16, 2025 | A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now