2025 CVE Vulnerabilities
45,347 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53256 | HIGH | 7.6 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMT... |
| CVE-2025-50528 | HIGH | 7.3 | 0.3% | Jun 27, 2025 | A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page par... |
| CVE-2025-36595 | HIGH | 7.2 | 0.5% | Jun 27, 2025 | Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically ... |
| CVE-2025-6766 | HIGH | 8.8 | 0.3% | Jun 27, 2025 | A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. It has been declared as... |
| CVE-2025-6765 | HIGH | 8.8 | 0.4% | Jun 27, 2025 | A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects s... |
| CVE-2025-6763 | HIGH | 8.2 | 1.2% | Jun 27, 2025 | A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. ... |
| CVE-2025-6762 | HIGH | 7.2 | 0.4% | Jun 27, 2025 | A vulnerability classified as critical has been found in diyhi bbs up to 6.8. This affects the function getUrl of the fi... |
| CVE-2025-52827 | HIGH | 8.8 | 0.3% | Jun 27, 2025 | Deserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from... |
| CVE-2025-52826 | HIGH | 8.8 | 0.3% | Jun 27, 2025 | Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a... |
| CVE-2025-52824 | HIGH | 8.8 | 0.3% | Jun 27, 2025 | Missing Authorization vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Exploiting Incorrectly Configured... |
| CVE-2025-52818 | HIGH | 8.2 | 0.2% | Jun 27, 2025 | Missing Authorization vulnerability in Dejan Jasnic Trusty Whistleblowing trusty-whistleblowing-solution allows Exploiti... |
| CVE-2025-52817 | HIGH | 8.2 | 0.3% | Jun 27, 2025 | Missing Authorization vulnerability in ZealousWeb Abandoned Contact Form 7 abandoned-contact-form-7 allows Exploiting In... |
| CVE-2025-52815 | HIGH | 8.1 | 0.4% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52814 | HIGH | 8.1 | 0.4% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52812 | HIGH | 8.1 | 0.4% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52811 | HIGH | 8.1 | 0.4% | Jun 27, 2025 | Path Traversal: '.../...//' vulnerability in Creanncy Davenport - Versatile Blog and Magazine WordPress Theme davenport ... |
| CVE-2025-52810 | HIGH | 8.1 | 0.4% | Jun 27, 2025 | Path Traversal vulnerability in TMRW-studio Katerio - Magazine allows PHP Local File Inclusion. This issue affects Kater... |
| CVE-2025-52809 | HIGH | 8.1 | 0.4% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52808 | HIGH | 8.1 | 0.4% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52799 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes LMS l... |
| CVE-2025-52778 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup... |
| CVE-2025-52774 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility ... |
| CVE-2025-52729 | HIGH | 8.1 | 0.4% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52727 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs CSS3 ... |
| CVE-2025-52726 | HIGH | 8.6 | 0.2% | Jun 27, 2025 | Incorrect Privilege Assignment vulnerability in pebas CouponXxL Custom Post Types couponxxl-cpt allows Privilege Escalat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now