2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41683 | HIGH | 8.8 | 0.7% | Jul 23, 2025 | An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of ... |
| CVE-2025-31701 | HIGH | 8.1 | 0.8% | Jul 23, 2025 | A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending sp... |
| CVE-2025-31700 | HIGH | 8.1 | 0.8% | Jul 23, 2025 | A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending sp... |
| CVE-2025-54441 | HIGH | 8.8 | 7.4% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-54439 | HIGH | 8.8 | 6.9% | Jul 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje... |
| CVE-2025-8021 | HIGH | 7.7 | 0.8% | Jul 23, 2025 | All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the... |
| CVE-2025-8020 | HIGH | 8.2 | 0.3% | Jul 23, 2025 | All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provid... |
| CVE-2025-7722 | HIGH | 8.8 | 0.4% | Jul 23, 2025 | The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.... |
| CVE-2025-6190 | HIGH | 8.8 | 0.4% | Jul 23, 2025 | The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within... |
| CVE-2025-8060 | HIGH | 8.8 | 0.8% | Jul 23, 2025 | A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is t... |
| CVE-2025-43022 | HIGH | 7.2 | 0.3% | Jul 22, 2025 | A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. T... |
| CVE-2025-8011 | HIGH | 8.8 | 0.3% | Jul 22, 2025 | Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2025-8010 | HIGH | 8.8 | 0.3% | Jul 22, 2025 | Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2025-7766 | HIGH | 8.6 | 1.7% | Jul 22, 2025 | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network d... |
| CVE-2025-54141 | HIGH | 7.5 | 0.8% | Jul 22, 2025 | ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and ... |
| CVE-2025-54140 | HIGH | 7.5 | 0.6% | Jul 22, 2025 | pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated pat... |
| CVE-2025-54138 | HIGH | 7.5 | 0.8% | Jul 22, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo... |
| CVE-2025-54137 | HIGH | 7.3 | 0.3% | Jul 22, 2025 | HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were dis... |
| CVE-2025-54072 | HIGH | 8.1 | 0.6% | Jul 22, 2025 | yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option i... |
| CVE-2025-53703 | HIGH | 8.7 | 0.1% | Jul 22, 2025 | DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted b... |
| CVE-2025-53538 | HIGH | 7.5 | 0.4% | Jul 22, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-48733 | HIGH | 8.7 | 0.4% | Jul 22, 2025 | DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication. This cou... |
| CVE-2025-41425 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack. This could allow an attacker to preven... |
| CVE-2025-8040 | HIGH | 8.8 | 0.3% | Jul 22, 2025 | Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these b... |
| CVE-2025-8039 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now