2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7119 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this... |
| CVE-2025-41672 | CRITICAL | 10 | 0.3% | Jul 7, 2025 | A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool a... |
| CVE-2025-48501 | CRITICAL | 9.8 | 1.3% | Jul 7, 2025 | An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an... |
| CVE-2025-7102 | CRITICAL | 9.8 | 0.3% | Jul 7, 2025 | A vulnerability was found in BoyunCMS up to 1.4.20. It has been declared as critical. This vulnerability affects unknown... |
| CVE-2025-7101 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This affects an unknown part of ... |
| CVE-2025-7100 | CRITICAL | 9.8 | 0.3% | Jul 7, 2025 | A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown fu... |
| CVE-2025-5333 | CRITICAL | 9.5 | 0.7% | Jul 6, 2025 | Remote attackers can execute arbitrary code in the context of the vulnerable service process. |
| CVE-2025-26850 | CRITICAL | 9.3 | 0.2% | Jul 5, 2025 | The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows p... |
| CVE-2025-48952 | CRITICAL | 9.4 | 0.5% | Jul 4, 2025 | NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentic... |
| CVE-2025-53484 | CRITICAL | 9.8 | 0.5% | Jul 4, 2025 | User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPag... |
| CVE-2025-52833 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS l... |
| CVE-2025-52832 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart I... |
| CVE-2025-52831 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video... |
| CVE-2025-52830 | CRITICAL | 9.3 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bSecure – Your Uni... |
| CVE-2025-49867 | CRITICAL | 9.8 | 0.3% | Jul 4, 2025 | Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue... |
| CVE-2025-49417 | CRITICAL | 9.8 | 0.4% | Jul 4, 2025 | Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiact... |
| CVE-2025-49414 | CRITICAL | 10 | 0.3% | Jul 4, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Using Maliciou... |
| CVE-2025-49302 | CRITICAL | 10 | 0.4% | Jul 4, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows... |
| CVE-2025-47479 | CRITICAL | 9.8 | 0.3% | Jul 4, 2025 | Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This iss... |
| CVE-2025-30933 | CRITICAL | 10 | 0.3% | Jul 4, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a... |
| CVE-2025-28983 | CRITICAL | 9.8 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Cli... |
| CVE-2025-23970 | CRITICAL | 9.8 | 0.7% | Jul 4, 2025 | Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation.... |
| CVE-2025-28951 | CRITICAL | 9.1 | 0.3% | Jul 4, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allow... |
| CVE-2025-53599 | CRITICAL | 9.8 | 0.4% | Jul 4, 2025 | Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted java... |
| CVE-2025-34089 | CRITICAL | 9.3 | 1.4% | Jul 3, 2025 | An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility develope... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now