2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28170 | HIGH | 7.6 | 0.3% | Jul 29, 2025 | Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with direct... |
| CVE-2025-51970 | HIGH | 7.7 | 0.2% | Jul 29, 2025 | A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 du... |
| CVE-2025-6505 | HIGH | 8.1 | 0.3% | Jul 29, 2025 | Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipe... |
| CVE-2025-6504 | HIGH | 8.4 | 0.2% | Jul 29, 2025 | In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-... |
| CVE-2025-6175 | HIGH | 7.2 | 0.2% | Jul 29, 2025 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Sp... |
| CVE-2025-7689 | HIGH | 8.8 | 0.3% | Jul 29, 2025 | The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tf... |
| CVE-2025-6495 | HIGH | 7.5 | 0.4% | Jul 29, 2025 | The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and inc... |
| CVE-2025-54769 | HIGH | 8.8 | 3.0% | Jul 29, 2025 | An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in... |
| CVE-2025-50486 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allo... |
| CVE-2025-50485 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 al... |
| CVE-2025-29534 | HIGH | 8.8 | 0.7% | Jul 28, 2025 | An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker ... |
| CVE-2025-8194 | HIGH | 7.5 | 0.6% | Jul 28, 2025 | There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar... |
| CVE-2025-50487 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management Sy... |
| CVE-2025-50484 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to... |
| CVE-2025-50492 | HIGH | 7.5 | 0.5% | Jul 28, 2025 | Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allo... |
| CVE-2025-50491 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v... |
| CVE-2025-50489 | HIGH | 7.5 | 0.5% | Jul 28, 2025 | Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System ... |
| CVE-2025-50488 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management Syst... |
| CVE-2025-54536 | HIGH | 8.8 | 0.1% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint |
| CVE-2025-54535 | HIGH | 7.5 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms |
| CVE-2025-54529 | HIGH | 7.5 | 0.1% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration |
| CVE-2025-54528 | HIGH | 8.8 | 0.1% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow |
| CVE-2025-50494 | HIGH | 7.5 | 0.4% | Jul 28, 2025 | Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v... |
| CVE-2025-50493 | HIGH | 7.5 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management S... |
| CVE-2025-50490 | HIGH | 7.5 | 0.4% | Jul 28, 2025 | Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management Syst... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now