2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24769 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-24765 | HIGH | 7.7 | 0.4% | Jun 27, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RobMarsh Image Shadow im... |
| CVE-2025-24760 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-23973 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dugudlabs SpecFit-... |
| CVE-2025-6761 | HIGH | 7.3 | 0.4% | Jun 27, 2025 | A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical.... |
| CVE-2025-2940 | HIGH | 7.2 | 0.3% | Jun 27, 2025 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers... |
| CVE-2025-36529 | HIGH | 8.6 | 1.2% | Jun 27, 2025 | An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnera... |
| CVE-2025-6752 | HIGH | 8.8 | 0.9% | Jun 27, 2025 | A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7450 and EA7500 up to 20250619 and classified as critica... |
| CVE-2025-6751 | HIGH | 8.8 | 0.6% | Jun 27, 2025 | A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the func... |
| CVE-2025-6736 | HIGH | 8.8 | 0.4% | Jun 27, 2025 | A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown func... |
| CVE-2025-6735 | HIGH | 8.8 | 0.4% | Jun 27, 2025 | A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file ... |
| CVE-2025-6734 | HIGH | 8.8 | 0.8% | Jun 26, 2025 | A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. This issue affects the fu... |
| CVE-2025-6733 | HIGH | 8.8 | 0.8% | Jun 26, 2025 | A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been declared as critical. This vulnerability aff... |
| CVE-2025-6732 | HIGH | 8.8 | 0.8% | Jun 26, 2025 | A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been classified as critical. This affects the fun... |
| CVE-2025-52904 | HIGH | 8 | 0.9% | Jun 26, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52903 | HIGH | 8 | 1.0% | Jun 26, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52477 | HIGH | 8.6 | 0.4% | Jun 26, 2025 | Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5... |
| CVE-2025-34048 | HIGH | 8.7 | 0.6% | Jun 26, 2025 | A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL... |
| CVE-2025-34047 | HIGH | 8.7 | 0.5% | Jun 26, 2025 | A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attack... |
| CVE-2025-34045 | HIGH | 7.5 | 4.3% | Jun 26, 2025 | A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework... |
| CVE-2025-53007 | HIGH | 8.9 | 0.4% | Jun 26, 2025 | arduino-esp32 provides an Arduino core for the ESP32. Versions prior to 3.3.0-RC1 and 3.2.1 contain a HTTP Response Spli... |
| CVE-2025-52887 | HIGH | 7.5 | 0.4% | Jun 26, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http head... |
| CVE-2025-51672 | HIGH | 8 | 0.4% | Jun 26, 2025 | A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. T... |
| CVE-2025-6710 | HIGH | 7.5 | 0.3% | Jun 26, 2025 | MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON input... |
| CVE-2025-6709 | HIGH | 7.5 | 0.5% | Jun 26, 2025 | The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now