2025 CVE Vulnerabilities
45,345 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34116 | HIGH | 8.7 | 1.1% | Jul 15, 2025 | A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI in... |
| CVE-2025-34115 | HIGH | 8.7 | 3.3% | Jul 15, 2025 | An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter... |
| CVE-2025-34113 | HIGH | 8.7 | 2.1% | Jul 15, 2025 | An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14... |
| CVE-2025-34109 | HIGH | 8.5 | 0.3% | Jul 15, 2025 | PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writ... |
| CVE-2025-34108 | HIGH | 8.6 | 0.9% | Jul 15, 2025 | A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. A... |
| CVE-2025-34107 | HIGH | 8.7 | 0.8% | Jul 15, 2025 | A buffer overflow vulnerability exists in the WinaXe FTP Client version 7.7 within the FTP banner parsing functionality,... |
| CVE-2025-34106 | HIGH | 8.4 | 0.3% | Jul 15, 2025 | A buffer overflow vulnerability exists in PDF Shaper versions 3.5 and 3.6 when converting a crafted PDF file to an image... |
| CVE-2025-7667 | HIGH | 8.1 | 0.3% | Jul 15, 2025 | The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-6265 | HIGH | 7.2 | 0.5% | Jul 15, 2025 | A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and... |
| CVE-2025-53836 | HIGH | 8.8 | 0.5% | Jul 15, 2025 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int... |
| CVE-2025-53823 | HIGH | 8.8 | 0.5% | Jul 14, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior ... |
| CVE-2025-53819 | HIGH | 7.9 | 0.1% | Jul 14, 2025 | Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated p... |
| CVE-2025-53818 | HIGH | 8.9 | 1.3% | Jul 14, 2025 | GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and ... |
| CVE-2025-53643 | HIGH | 7.5 | 0.3% | Jul 14, 2025 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python par... |
| CVE-2025-53623 | HIGH | 8.1 | 0.7% | Jul 14, 2025 | The Job Iteration API is an an extension for ActiveJob that make jobs interruptible and resumable Versions prior to 1.11... |
| CVE-2025-53019 | HIGH | 7.5 | 0.5% | Jul 14, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.... |
| CVE-2025-53015 | HIGH | 7.5 | 0.7% | Jul 14, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.... |
| CVE-2025-7628 | HIGH | 8.1 | 0.7% | Jul 14, 2025 | A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been... |
| CVE-2025-7626 | HIGH | 7.5 | 0.5% | Jul 14, 2025 | A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and cla... |
| CVE-2025-7616 | HIGH | 7.5 | 0.4% | Jul 14, 2025 | A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this iss... |
| CVE-2025-7615 | HIGH | 8.8 | 2.6% | Jul 14, 2025 | A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the funct... |
| CVE-2025-7614 | HIGH | 8.8 | 2.6% | Jul 14, 2025 | A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of ... |
| CVE-2025-7613 | HIGH | 8.8 | 2.6% | Jul 14, 2025 | A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function Clo... |
| CVE-2025-7603 | HIGH | 7.3 | 0.9% | Jul 14, 2025 | A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown funct... |
| CVE-2025-27582 | HIGH | 7.6 | 0.2% | Jul 14, 2025 | The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now