2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34110 | CRITICAL | 9.3 | 1.3% | Jul 15, 2025 | A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att... |
| CVE-2025-34105 | CRITICAL | 10 | 1.0% | Jul 15, 2025 | A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28,... |
| CVE-2025-34104 | CRITICAL | 9.4 | 0.9% | Jul 15, 2025 | An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin... |
| CVE-2025-34103 | CRITICAL | 9.3 | 4.2% | Jul 15, 2025 | An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due... |
| CVE-2025-34068 | CRITICAL | 9.3 | 0.9% | Jul 15, 2025 | An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.... |
| CVE-2025-3621 | CRITICAL | 9.6 | 0.8% | Jul 15, 2025 | Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on ho... |
| CVE-2025-7360 | CRITICAL | 9.8 | 1.3% | Jul 15, 2025 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab... |
| CVE-2025-7341 | CRITICAL | 9.8 | 1.1% | Jul 15, 2025 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab... |
| CVE-2025-7340 | CRITICAL | 9.8 | 1.6% | Jul 15, 2025 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab... |
| CVE-2025-5394 | CRITICAL | 9.8 | 47.8% | Jul 15, 2025 | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads ... |
| CVE-2025-5393 | CRITICAL | 9.1 | 0.5% | Jul 15, 2025 | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion... |
| CVE-2025-53890 | CRITICAL | 9.8 | 1.1% | Jul 15, 2025 | pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoa... |
| CVE-2025-53835 | CRITICAL | 9 | 0.3% | Jul 14, 2025 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int... |
| CVE-2025-53833 | CRITICAL | 10 | 9.4% | Jul 14, 2025 | LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior ... |
| CVE-2025-53825 | CRITICAL | 9.8 | 0.5% | Jul 14, 2025 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deplo... |
| CVE-2025-53639 | CRITICAL | 9.8 | 0.4% | Jul 14, 2025 | MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certai... |
| CVE-2025-53101 | CRITICAL | 9.8 | 0.8% | Jul 14, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.... |
| CVE-2025-7627 | CRITICAL | 9.8 | 0.4% | Jul 14, 2025 | A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classifi... |
| CVE-2025-53014 | CRITICAL | 9.8 | 0.6% | Jul 14, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0... |
| CVE-2025-7612 | CRITICAL | 9.8 | 0.5% | Jul 14, 2025 | A vulnerability was found in code-projects Mobile Shop 1.0. It has been declared as critical. This vulnerability affects... |
| CVE-2025-7611 | CRITICAL | 9.8 | 0.4% | Jul 14, 2025 | A vulnerability was found in code-projects Wedding Reservation 1.0. It has been classified as critical. This affects an ... |
| CVE-2025-50756 | CRITICAL | 9.8 | 1.9% | Jul 14, 2025 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newp... |
| CVE-2025-7610 | CRITICAL | 9.8 | 0.4% | Jul 14, 2025 | A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this i... |
| CVE-2025-7609 | CRITICAL | 9.8 | 0.4% | Jul 14, 2025 | A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vu... |
| CVE-2025-7608 | CRITICAL | 9.8 | 0.4% | Jul 14, 2025 | A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now