2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-28170HIGH7.6Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with direct...
CVE-2025-51970HIGH7.7A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 du...
CVE-2025-6505HIGH8.1Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipe...
CVE-2025-6504HIGH8.4In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-...
CVE-2025-6175HIGH7.2Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Sp...
CVE-2025-7689HIGH8.8The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tf...
CVE-2025-6495HIGH7.5The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and inc...
CVE-2025-54769HIGH8.8An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in...
CVE-2025-50486HIGH7.1Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allo...
CVE-2025-50485HIGH7.1Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 al...
CVE-2025-29534HIGH8.8An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker ...
CVE-2025-8194HIGH7.5There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar...
CVE-2025-50487HIGH7.1Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management Sy...
CVE-2025-50484HIGH7.1Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to...
CVE-2025-50492HIGH7.5Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allo...
CVE-2025-50491HIGH7.1Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v...
CVE-2025-50489HIGH7.5Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System ...
CVE-2025-50488HIGH7.1Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management Syst...
CVE-2025-54536HIGH8.8In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
CVE-2025-54535HIGH7.5In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
CVE-2025-54529HIGH7.5In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
CVE-2025-54528HIGH8.8In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
CVE-2025-50494HIGH7.5Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v...
CVE-2025-50493HIGH7.5Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management S...
CVE-2025-50490HIGH7.5Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management Syst...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now