2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25257 | CRITICAL | 9.8 | 96.7% | Jul 17, 2025 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi... |
| CVE-2025-53928 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution ... |
| CVE-2025-51630 | CRITICAL | 9.8 | 0.5% | Jul 17, 2025 | TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the functi... |
| CVE-2025-7712 | CRITICAL | 9.1 | 0.8% | Jul 17, 2025 | The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation... |
| CVE-2025-5396 | CRITICAL | 9.8 | 0.7% | Jul 17, 2025 | The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0... |
| CVE-2025-34132 | CRITICAL | 9.3 | 1.8% | Jul 16, 2025 | A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_... |
| CVE-2025-34127 | CRITICAL | 9.3 | 1.1% | Jul 16, 2025 | A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted messag... |
| CVE-2025-34125 | CRITICAL | 9.3 | 3.1% | Jul 16, 2025 | An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D... |
| CVE-2025-34121 | CRITICAL | 9.3 | 1.7% | Jul 16, 2025 | An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and inc... |
| CVE-2025-34117 | CRITICAL | 9.3 | 22.9% | Jul 16, 2025 | A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior t... |
| CVE-2025-37107 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. |
| CVE-2025-37106 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior ... |
| CVE-2025-37105 | CRITICAL | 9.8 | 0.6% | Jul 16, 2025 | An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. |
| CVE-2025-20337 | CRITICAL | 10 | 65.1% | Jul 16, 2025 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec... |
| CVE-2025-53937 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-34300 | CRITICAL | 10 | 49.1% | Jul 16, 2025 | A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ci... |
| CVE-2025-52836 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Pr... |
| CVE-2025-52714 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele... |
| CVE-2025-48300 | CRITICAL | 9.1 | 0.4% | Jul 16, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg groundhogg allows Upload a Web ... |
| CVE-2025-30973 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in Codexpert, Inc CoSchool LMS coschool allows Object Injection.This iss... |
| CVE-2025-30949 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object I... |
| CVE-2025-30936 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for ... |
| CVE-2025-29009 | CRITICAL | 10 | 0.5% | Jul 16, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCo... |
| CVE-2025-28982 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes... |
| CVE-2025-28961 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now