2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5014 | HIGH | 8.8 | 0.7% | Jul 2, 2025 | The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff... |
| CVE-2025-4381 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via... |
| CVE-2025-36630 | HIGH | 7.1 | 0.2% | Jul 2, 2025 | In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit... |
| CVE-2025-49741 | HIGH | 7.5 | 3.4% | Jul 1, 2025 | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a ... |
| CVE-2025-53107 | HIGH | 7.5 | 22.1% | Jul 1, 2025 | @cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is ... |
| CVE-2025-53100 | HIGH | 8.6 | 1.3% | Jul 1, 2025 | RestDB's Codehooks.io MCP Server is an MCP server on the Codehooks.io platform. Prior to version 0.2.2, the MCP server i... |
| CVE-2025-45081 | HIGH | 8.8 | 0.3% | Jul 1, 2025 | Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data. |
| CVE-2025-34081 | HIGH | 7.5 | 0.6% | Jul 1, 2025 | The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may cont... |
| CVE-2025-6297 | HIGH | 8.2 | 0.3% | Jul 1, 2025 | It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a... |
| CVE-2025-53099 | HIGH | 7.5 | 0.7% | Jul 1, 2025 | Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a ... |
| CVE-2025-37098 | HIGH | 7.5 | 30.4% | Jul 1, 2025 | A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. |
| CVE-2025-34066 | HIGH | 8.3 | 0.3% | Jul 1, 2025 | An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with... |
| CVE-2025-34059 | HIGH | 8.7 | 0.4% | Jul 1, 2025 | An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username... |
| CVE-2025-34058 | HIGH | 8.7 | 0.9% | Jul 1, 2025 | Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate ... |
| CVE-2025-6953 | HIGH | 8.8 | 0.8% | Jul 1, 2025 | A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an un... |
| CVE-2025-37097 | HIGH | 7.5 | 0.4% | Jul 1, 2025 | A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service |
| CVE-2025-36582 | HIGH | 7.5 | 0.2% | Jul 1, 2025 | Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorit... |
| CVE-2025-6940 | HIGH | 8.8 | 0.8% | Jul 1, 2025 | A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability ... |
| CVE-2025-6939 | HIGH | 8.8 | 0.8% | Jul 1, 2025 | A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown f... |
| CVE-2025-53095 | HIGH | 8.8 | 0.2% | Jul 1, 2025 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks p... |
| CVE-2025-53003 | HIGH | 8.2 | 0.3% | Jul 1, 2025 | The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config ... |
| CVE-2025-6931 | HIGH | 7.4 | 1.6% | Jun 30, 2025 | A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this vulne... |
| CVE-2025-6930 | HIGH | 8.8 | 0.3% | Jun 30, 2025 | A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown fu... |
| CVE-2025-6554 | HIGH | 8.1 | 6.6% | Jun 30, 2025 | Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v... |
| CVE-2025-6929 | HIGH | 8.8 | 0.3% | Jun 30, 2025 | A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects som... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now