2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53006 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreS... |
| CVE-2025-34073 | CRITICAL | 10 | 3.9% | Jul 2, 2025 | An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote atta... |
| CVE-2025-34072 | CRITICAL | 9.3 | 0.4% | Jul 2, 2025 | A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automat... |
| CVE-2025-34071 | CRITICAL | 9.8 | 0.7% | Jul 2, 2025 | A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload a... |
| CVE-2025-34070 | CRITICAL | 9.8 | 0.7% | Jul 2, 2025 | A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remot... |
| CVE-2025-34069 | CRITICAL | 9.8 | 0.6% | Jul 2, 2025 | An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and... |
| CVE-2025-34067 | CRITICAL | 10 | 18.7% | Jul 2, 2025 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Se... |
| CVE-2025-5746 | CRITICAL | 9.8 | 0.6% | Jul 2, 2025 | The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads ... |
| CVE-2025-4689 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus... |
| CVE-2025-4380 | CRITICAL | 9.8 | 28.2% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus... |
| CVE-2025-52101 | CRITICAL | 9.8 | 0.4% | Jul 1, 2025 | linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attacke... |
| CVE-2025-45006 | CRITICAL | 9.1 | 0.4% | Jul 1, 2025 | Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec co... |
| CVE-2025-53104 | CRITICAL | 9.1 | 1.2% | Jul 1, 2025 | gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commi... |
| CVE-2025-37099 | CRITICAL | 9.8 | 0.6% | Jul 1, 2025 | A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. |
| CVE-2025-6963 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerabilit... |
| CVE-2025-6962 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects a... |
| CVE-2025-6961 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected ... |
| CVE-2025-6960 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability classified as critical was found in Campcodes Employee Management System 1.0. Affected by this vulnerabi... |
| CVE-2025-6959 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability classified as critical has been found in Campcodes Employee Management System 1.0. Affected is an unknow... |
| CVE-2025-6958 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0. It has been rated as critical. This issue affects... |
| CVE-2025-6957 | CRITICAL | 9.8 | 0.5% | Jul 1, 2025 | A vulnerability was found in Campcodes Employee Management System 1.0. It has been declared as critical. This vulnerabil... |
| CVE-2025-34064 | CRITICAL | 9 | 0.4% | Jul 1, 2025 | A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket... |
| CVE-2025-34063 | CRITICAL | 10 | 0.5% | Jul 1, 2025 | A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure o... |
| CVE-2025-34060 | CRITICAL | 10 | 0.7% | Jul 1, 2025 | A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handli... |
| CVE-2025-34056 | CRITICAL | 9.4 | 1.8% | Jul 1, 2025 | An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, whic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now