2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-37107 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. |
| CVE-2025-37106 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior ... |
| CVE-2025-37105 | CRITICAL | 9.8 | 0.6% | Jul 16, 2025 | An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. |
| CVE-2025-20337 | CRITICAL | 10 | 65.1% | Jul 16, 2025 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec... |
| CVE-2025-53937 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-34300 | CRITICAL | 10 | 49.1% | Jul 16, 2025 | A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ci... |
| CVE-2025-52836 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Pr... |
| CVE-2025-52714 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele... |
| CVE-2025-48300 | CRITICAL | 9.1 | 0.4% | Jul 16, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg groundhogg allows Upload a Web ... |
| CVE-2025-30973 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in Codexpert, Inc CoSchool LMS coschool allows Object Injection.This iss... |
| CVE-2025-30949 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object I... |
| CVE-2025-30936 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for ... |
| CVE-2025-29009 | CRITICAL | 10 | 0.5% | Jul 16, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCo... |
| CVE-2025-28982 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes... |
| CVE-2025-28961 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection... |
| CVE-2025-28959 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haide... |
| CVE-2025-24759 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPr... |
| CVE-2025-54010 | CRITICAL | 9.6 | 0.2% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Re... |
| CVE-2025-7673 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior... |
| CVE-2025-52689 | CRITICAL | 9.8 | 11.0% | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with a... |
| CVE-2025-52688 | CRITICAL | 9.8 | 22.5% | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the acce... |
| CVE-2025-49841 | CRITICAL | 9.8 | 0.6% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
| CVE-2025-49840 | CRITICAL | 9.8 | 0.6% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
| CVE-2025-49839 | CRITICAL | 9.8 | 0.7% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
| CVE-2025-49838 | CRITICAL | 9.8 | 0.7% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now