2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7454 | CRITICAL | 9.8 | 0.4% | Jul 11, 2025 | A vulnerability classified as critical has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Aff... |
| CVE-2025-52950 | CRITICAL | 9.6 | 0.4% | Jul 11, 2025 | A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based atta... |
| CVE-2025-50121 | CRITICAL | 9.5 | 15.3% | Jul 11, 2025 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist... |
| CVE-2025-5392 | CRITICAL | 9.8 | 0.8% | Jul 11, 2025 | The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 ... |
| CVE-2025-30026 | CRITICAL | 9.8 | 0.6% | Jul 11, 2025 | The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required. |
| CVE-2025-30023 | CRITICAL | 9 | 0.5% | Jul 11, 2025 | The communication protocol used between client and server had a flaw that could lead to an authenticated user performing... |
| CVE-2025-7401 | CRITICAL | 9.8 | 0.5% | Jul 11, 2025 | The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and w... |
| CVE-2025-7436 | CRITICAL | 9.8 | 0.4% | Jul 11, 2025 | A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been declared as critical. This ... |
| CVE-2025-52579 | CRITICAL | 9.4 | 0.4% | Jul 11, 2025 | Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to d... |
| CVE-2025-2523 | CRITICAL | 9.4 | 0.7% | Jul 10, 2025 | The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Con... |
| CVE-2025-53633 | CRITICAL | 9.8 | 0.5% | Jul 10, 2025 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.... |
| CVE-2025-53632 | CRITICAL | 9.1 | 0.7% | Jul 10, 2025 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.... |
| CVE-2025-34102 | CRITICAL | 9.3 | 6.8% | Jul 10, 2025 | A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploi... |
| CVE-2025-34101 | CRITICAL | 9.3 | 3.1% | Jul 10, 2025 | An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, i... |
| CVE-2025-34100 | CRITICAL | 9.3 | 2.3% | Jul 10, 2025 | An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file man... |
| CVE-2025-34099 | CRITICAL | 9.3 | 1.2% | Jul 10, 2025 | An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vici... |
| CVE-2025-34096 | CRITICAL | 9.3 | 1.1% | Jul 10, 2025 | A stack-based buffer overflow vulnerability exists in Easy File Sharing HTTP Server version 7.2. The flaw is triggered w... |
| CVE-2025-34095 | CRITICAL | 9.3 | 4.4% | Jul 10, 2025 | An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial inter... |
| CVE-2025-7411 | CRITICAL | 9.8 | 0.4% | Jul 10, 2025 | A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulne... |
| CVE-2025-53378 | CRITICAL | 9.8 | 0.6% | Jul 10, 2025 | A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have all... |
| CVE-2025-53371 | CRITICAL | 9.1 | 0.3% | Jul 10, 2025 | DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel... |
| CVE-2025-7410 | CRITICAL | 9.8 | 0.4% | Jul 10, 2025 | A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unkno... |
| CVE-2025-7409 | CRITICAL | 9.8 | 0.4% | Jul 10, 2025 | A vulnerability was found in code-projects Mobile Shop 1.0 and classified as critical. This issue affects some unknown p... |
| CVE-2025-47812 | CRITICAL | 10 | 95.3% | Jul 10, 2025 | In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o... |
| CVE-2025-23048 | CRITICAL | 9.1 | 1.0% | Jul 10, 2025 | In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clien... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now