2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28959 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haide... |
| CVE-2025-24759 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPr... |
| CVE-2025-54010 | CRITICAL | 9.6 | 0.2% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Re... |
| CVE-2025-7673 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior... |
| CVE-2025-52689 | CRITICAL | 9.8 | 11.0% | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with a... |
| CVE-2025-52688 | CRITICAL | 9.8 | 22.5% | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the acce... |
| CVE-2025-49841 | CRITICAL | 9.8 | 0.6% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
| CVE-2025-49840 | CRITICAL | 9.8 | 0.6% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
| CVE-2025-49839 | CRITICAL | 9.8 | 0.7% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
| CVE-2025-49838 | CRITICAL | 9.8 | 0.7% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
| CVE-2025-49837 | CRITICAL | 9.8 | 0.7% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
| CVE-2025-49836 | CRITICAL | 9.8 | 3.3% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in... |
| CVE-2025-49835 | CRITICAL | 9.8 | 3.4% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in... |
| CVE-2025-49834 | CRITICAL | 9.8 | 3.3% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in... |
| CVE-2025-49833 | CRITICAL | 9.8 | 3.4% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in... |
| CVE-2025-49831 | CRITICAL | 9.8 | 1.2% | Jul 15, 2025 | An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misco... |
| CVE-2025-50067 | CRITICAL | 9 | 0.3% | Jul 15, 2025 | Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are aff... |
| CVE-2025-49827 | CRITICAL | 9.8 | 1.4% | Jul 15, 2025 | Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.... |
| CVE-2025-41238 | CRITICAL | 9.3 | 0.4% | Jul 15, 2025 | VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controll... |
| CVE-2025-41237 | CRITICAL | 9.3 | 0.4% | Jul 15, 2025 | VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that... |
| CVE-2025-41236 | CRITICAL | 9.3 | 2.2% | Jul 15, 2025 | VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A... |
| CVE-2025-53826 | CRITICAL | 9.8 | 0.5% | Jul 15, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52376 | CRITICAL | 9.8 | 9.1% | Jul 15, 2025 | An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router ... |
| CVE-2025-34112 | CRITICAL | 10 | 2.0% | Jul 15, 2025 | An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpr... |
| CVE-2025-34111 | CRITICAL | 9.8 | 1.5% | Jul 15, 2025 | An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now