2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6962 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects a... |
| CVE-2025-6961 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected ... |
| CVE-2025-6960 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability classified as critical was found in Campcodes Employee Management System 1.0. Affected by this vulnerabi... |
| CVE-2025-6959 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability classified as critical has been found in Campcodes Employee Management System 1.0. Affected is an unknow... |
| CVE-2025-6958 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0. It has been rated as critical. This issue affects... |
| CVE-2025-6957 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0. It has been declared as critical. This vulnerabil... |
| CVE-2025-34064 | CRITICAL | 9 | 0.4% | Jul 1, 2025 | A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket... |
| CVE-2025-34063 | CRITICAL | 10 | 0.5% | Jul 1, 2025 | A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure o... |
| CVE-2025-34060 | CRITICAL | 10 | 0.7% | Jul 1, 2025 | A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handli... |
| CVE-2025-34056 | CRITICAL | 9.4 | 1.8% | Jul 1, 2025 | An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, whic... |
| CVE-2025-34055 | CRITICAL | 9.4 | 1.5% | Jul 1, 2025 | An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint... |
| CVE-2025-34054 | CRITICAL | 10 | 2.7% | Jul 1, 2025 | An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use... |
| CVE-2025-6956 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects ... |
| CVE-2025-6955 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue... |
| CVE-2025-6954 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this ... |
| CVE-2025-49029 | CRITICAL | 9.1 | 2.1% | Jul 1, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget cus... |
| CVE-2025-45872 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter. |
| CVE-2025-49480 | CRITICAL | 9.1 | 0.2% | Jul 1, 2025 | Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lz... |
| CVE-2025-49492 | CRITICAL | 9.8 | 0.3% | Jul 1, 2025 | Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun. This vulnerability is associated with pr... |
| CVE-2025-41656 | CRITICAL | 10 | 10.0% | Jul 1, 2025 | An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the a... |
| CVE-2025-41648 | CRITICAL | 9.8 | 0.7% | Jul 1, 2025 | An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possibl... |
| CVE-2025-6934 | CRITICAL | 9.8 | 22.3% | Jul 1, 2025 | The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Respo... |
| CVE-2025-6938 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue a... |
| CVE-2025-6937 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. This vuln... |
| CVE-2025-53005 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypas... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now