2025 CVE Vulnerabilities
45,347 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28946 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-27361 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thhake Photo Expre... |
| CVE-2025-25173 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FasterThemes FastB... |
| CVE-2025-25171 | HIGH | 8.8 | 0.4% | Jun 27, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Convers Lab WP SmartPay smartpay allows Authen... |
| CVE-2025-24774 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - C... |
| CVE-2025-24769 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-24765 | HIGH | 7.7 | 0.4% | Jun 27, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RobMarsh Image Shadow im... |
| CVE-2025-24760 | HIGH | 8.1 | 0.5% | Jun 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-23973 | HIGH | 7.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dugudlabs SpecFit-... |
| CVE-2025-6761 | HIGH | 7.3 | 0.4% | Jun 27, 2025 | A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical.... |
| CVE-2025-2940 | HIGH | 7.2 | 0.3% | Jun 27, 2025 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all vers... |
| CVE-2025-36529 | HIGH | 8.6 | 1.2% | Jun 27, 2025 | An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnera... |
| CVE-2025-6752 | HIGH | 8.8 | 0.9% | Jun 27, 2025 | A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7450 and EA7500 up to 20250619 and classified as critica... |
| CVE-2025-6751 | HIGH | 8.8 | 0.6% | Jun 27, 2025 | A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the func... |
| CVE-2025-6736 | HIGH | 8.8 | 0.4% | Jun 27, 2025 | A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown func... |
| CVE-2025-6735 | HIGH | 8.8 | 0.4% | Jun 27, 2025 | A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file ... |
| CVE-2025-6734 | HIGH | 8.8 | 0.8% | Jun 26, 2025 | A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. This issue affects the fu... |
| CVE-2025-6733 | HIGH | 8.8 | 0.8% | Jun 26, 2025 | A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been declared as critical. This vulnerability aff... |
| CVE-2025-6732 | HIGH | 8.8 | 0.8% | Jun 26, 2025 | A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been classified as critical. This affects the fun... |
| CVE-2025-52904 | HIGH | 8 | 0.9% | Jun 26, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52903 | HIGH | 8 | 1.0% | Jun 26, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-52477 | HIGH | 8.6 | 0.4% | Jun 26, 2025 | Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5... |
| CVE-2025-34048 | HIGH | 8.7 | 0.6% | Jun 26, 2025 | A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL... |
| CVE-2025-34047 | HIGH | 8.7 | 0.5% | Jun 26, 2025 | A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attack... |
| CVE-2025-34045 | HIGH | 7.5 | 4.3% | Jun 26, 2025 | A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now