2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34082 | CRITICAL | 9.3 | 5.3% | Jul 3, 2025 | A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Sh... |
| CVE-2025-34061 | CRITICAL | 9.3 | 1.2% | Jul 3, 2025 | A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code ... |
| CVE-2025-23968 | CRITICAL | 9.1 | 0.4% | Jul 3, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Uploa... |
| CVE-2025-27456 | CRITICAL | 9.8 | 0.5% | Jul 3, 2025 | The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attemp... |
| CVE-2025-27449 | CRITICAL | 9.8 | 0.5% | Jul 3, 2025 | The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a sh... |
| CVE-2025-1710 | CRITICAL | 9.8 | 0.5% | Jul 3, 2025 | The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts wi... |
| CVE-2025-34074 | CRITICAL | 9.4 | 1.1% | Jul 2, 2025 | An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design i... |
| CVE-2025-45813 | CRITICAL | 9.8 | 0.4% | Jul 2, 2025 | ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials. |
| CVE-2025-45814 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v... |
| CVE-2025-20309 | CRITICAL | 10 | 1.1% | Jul 2, 2025 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma... |
| CVE-2025-53006 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreS... |
| CVE-2025-34073 | CRITICAL | 10 | 3.9% | Jul 2, 2025 | An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote atta... |
| CVE-2025-34072 | CRITICAL | 9.3 | 0.4% | Jul 2, 2025 | A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automat... |
| CVE-2025-34071 | CRITICAL | 9.8 | 0.7% | Jul 2, 2025 | A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload a... |
| CVE-2025-34070 | CRITICAL | 9.8 | 0.7% | Jul 2, 2025 | A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remot... |
| CVE-2025-34069 | CRITICAL | 9.8 | 0.6% | Jul 2, 2025 | An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and... |
| CVE-2025-34067 | CRITICAL | 10 | 18.7% | Jul 2, 2025 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Se... |
| CVE-2025-5746 | CRITICAL | 9.8 | 0.6% | Jul 2, 2025 | The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads ... |
| CVE-2025-4689 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus... |
| CVE-2025-4380 | CRITICAL | 9.8 | 28.2% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus... |
| CVE-2025-52101 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attacke... |
| CVE-2025-45006 | CRITICAL | 9.1 | 0.4% | Jul 1, 2025 | Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec co... |
| CVE-2025-53104 | CRITICAL | 9.1 | 1.2% | Jul 1, 2025 | gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commi... |
| CVE-2025-37099 | CRITICAL | 9.8 | 0.6% | Jul 1, 2025 | A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. |
| CVE-2025-6963 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerabilit... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now