2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49837 | CRITICAL | 9.8 | 0.7% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe de... |
| CVE-2025-49836 | CRITICAL | 9.8 | 3.3% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in... |
| CVE-2025-49835 | CRITICAL | 9.8 | 3.4% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in... |
| CVE-2025-49834 | CRITICAL | 9.8 | 3.3% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in... |
| CVE-2025-49833 | CRITICAL | 9.8 | 3.4% | Jul 15, 2025 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command in... |
| CVE-2025-49831 | CRITICAL | 9.8 | 1.2% | Jul 15, 2025 | An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misco... |
| CVE-2025-50067 | CRITICAL | 9 | 0.3% | Jul 15, 2025 | Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are aff... |
| CVE-2025-49827 | CRITICAL | 9.8 | 1.4% | Jul 15, 2025 | Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.... |
| CVE-2025-41238 | CRITICAL | 9.3 | 0.4% | Jul 15, 2025 | VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controll... |
| CVE-2025-41237 | CRITICAL | 9.3 | 0.4% | Jul 15, 2025 | VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that... |
| CVE-2025-41236 | CRITICAL | 9.3 | 2.2% | Jul 15, 2025 | VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A... |
| CVE-2025-53826 | CRITICAL | 9.8 | 0.5% | Jul 15, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52376 | CRITICAL | 9.8 | 9.1% | Jul 15, 2025 | An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router ... |
| CVE-2025-34112 | CRITICAL | 10 | 2.0% | Jul 15, 2025 | An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpr... |
| CVE-2025-34111 | CRITICAL | 9.8 | 1.5% | Jul 15, 2025 | An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via th... |
| CVE-2025-34110 | CRITICAL | 9.3 | 1.3% | Jul 15, 2025 | A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att... |
| CVE-2025-34105 | CRITICAL | 10 | 1.0% | Jul 15, 2025 | A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28,... |
| CVE-2025-34104 | CRITICAL | 9.4 | 0.9% | Jul 15, 2025 | An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin... |
| CVE-2025-34103 | CRITICAL | 9.3 | 4.2% | Jul 15, 2025 | An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due... |
| CVE-2025-34068 | CRITICAL | 9.3 | 0.9% | Jul 15, 2025 | An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.... |
| CVE-2025-3621 | CRITICAL | 9.6 | 0.8% | Jul 15, 2025 | Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on ho... |
| CVE-2025-7360 | CRITICAL | 9.8 | 1.3% | Jul 15, 2025 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab... |
| CVE-2025-7341 | CRITICAL | 9.8 | 1.1% | Jul 15, 2025 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab... |
| CVE-2025-7340 | CRITICAL | 9.8 | 1.6% | Jul 15, 2025 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab... |
| CVE-2025-5394 | CRITICAL | 9.8 | 47.8% | Jul 15, 2025 | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now