2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53633 | CRITICAL | 9.8 | 0.5% | Jul 10, 2025 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.... |
| CVE-2025-53632 | CRITICAL | 9.1 | 0.7% | Jul 10, 2025 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.... |
| CVE-2025-34102 | CRITICAL | 9.3 | 6.8% | Jul 10, 2025 | A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploi... |
| CVE-2025-34101 | CRITICAL | 9.3 | 3.1% | Jul 10, 2025 | An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, i... |
| CVE-2025-34100 | CRITICAL | 9.3 | 2.3% | Jul 10, 2025 | An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file man... |
| CVE-2025-34099 | CRITICAL | 9.3 | 1.2% | Jul 10, 2025 | An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vici... |
| CVE-2025-34096 | CRITICAL | 9.3 | 1.1% | Jul 10, 2025 | A stack-based buffer overflow vulnerability exists in Easy File Sharing HTTP Server version 7.2. The flaw is triggered w... |
| CVE-2025-34095 | CRITICAL | 9.3 | 4.4% | Jul 10, 2025 | An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial inter... |
| CVE-2025-7411 | CRITICAL | 9.8 | 0.4% | Jul 10, 2025 | A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulne... |
| CVE-2025-53378 | CRITICAL | 9.8 | 0.6% | Jul 10, 2025 | A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have all... |
| CVE-2025-53371 | CRITICAL | 9.1 | 0.3% | Jul 10, 2025 | DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel... |
| CVE-2025-7410 | CRITICAL | 9.8 | 0.4% | Jul 10, 2025 | A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unkno... |
| CVE-2025-7409 | CRITICAL | 9.8 | 0.4% | Jul 10, 2025 | A vulnerability was found in code-projects Mobile Shop 1.0 and classified as critical. This issue affects some unknown p... |
| CVE-2025-47812 | CRITICAL | 10 | 95.3% | Jul 10, 2025 | In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o... |
| CVE-2025-23048 | CRITICAL | 9.1 | 1.0% | Jul 10, 2025 | In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clien... |
| CVE-2025-46788 | CRITICAL | 9.1 | 0.2% | Jul 10, 2025 | Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to cond... |
| CVE-2025-53624 | CRITICAL | 10 | 1.8% | Jul 9, 2025 | The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docus... |
| CVE-2025-53620 | CRITICAL | 9.2 | 0.3% | Jul 9, 2025 | @builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the ... |
| CVE-2025-53546 | CRITICAL | 9.1 | 0.3% | Jul 9, 2025 | Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-comm... |
| CVE-2025-6514 | CRITICAL | 9.6 | 76.6% | Jul 9, 2025 | mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the aut... |
| CVE-2025-3499 | CRITICAL | 10 | 1.0% | Jul 9, 2025 | The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086)... |
| CVE-2025-3498 | CRITICAL | 9.9 | 0.3% | Jul 9, 2025 | An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 -... |
| CVE-2025-7220 | CRITICAL | 9.8 | 0.4% | Jul 9, 2025 | A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this... |
| CVE-2025-7219 | CRITICAL | 9.8 | 0.4% | Jul 9, 2025 | A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an... |
| CVE-2025-7218 | CRITICAL | 9.8 | 0.4% | Jul 9, 2025 | A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now