2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53902 | MEDIUM | 4.3 | 0.3% | Jul 29, 2025 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com... |
| CVE-2025-53541 | MEDIUM | 5.4 | 0.2% | Jul 29, 2025 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com... |
| CVE-2025-52899 | MEDIUM | 5.3 | 0.3% | Jul 29, 2025 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com... |
| CVE-2025-51045 | MEDIUM | 6.5 | 0.2% | Jul 29, 2025 | Phpgurukul Pre-School Enrollment System 1.0 contains a SQL injection vulnerability in the /admin/password-recovery.php f... |
| CVE-2025-51044 | MEDIUM | 6.5 | 0.2% | Jul 29, 2025 | phpgurukul Nipah virus (NiV) Testing Management System 1.0 contains a SQL injection vulnerability in the /new-user-testi... |
| CVE-2025-52284 | MEDIUM | 6.5 | 2.2% | Jul 29, 2025 | Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 functio... |
| CVE-2025-2179 | MEDIUM | 6.8 | 0.1% | Jul 29, 2025 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a ... |
| CVE-2025-27514 | MEDIUM | 5.4 | 0.2% | Jul 29, 2025 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2025-5922 | MEDIUM | 4.8 | 0.1% | Jul 29, 2025 | Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and r... |
| CVE-2025-28171 | MEDIUM | 6.5 | 0.3% | Jul 29, 2025 | An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the ... |
| CVE-2025-28172 | MEDIUM | 6.5 | 0.3% | Jul 29, 2025 | Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Att... |
| CVE-2025-52358 | MEDIUM | 6.3 | 0.3% | Jul 29, 2025 | A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Lo... |
| CVE-2025-6060 | MEDIUM | 5.4 | 0.2% | Jul 29, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Softwa... |
| CVE-2025-54422 | MEDIUM | 5.5 | 0.1% | Jul 29, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.... |
| CVE-2025-41241 | MEDIUM | 4.4 | 0.3% | Jul 29, 2025 | VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and ha... |
| CVE-2025-40686 | MEDIUM | 6.1 | 0.2% | Jul 29, 2025 | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ... |
| CVE-2025-40685 | MEDIUM | 6.1 | 0.2% | Jul 29, 2025 | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ... |
| CVE-2025-40684 | MEDIUM | 6.1 | 0.2% | Jul 29, 2025 | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ... |
| CVE-2025-40683 | MEDIUM | 6.1 | 0.2% | Jul 29, 2025 | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ... |
| CVE-2025-5587 | MEDIUM | 6.4 | 0.3% | Jul 29, 2025 | The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in al... |
| CVE-2025-8216 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in a... |
| CVE-2025-8196 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cust... |
| CVE-2025-6730 | MEDIUM | 4.3 | 0.2% | Jul 29, 2025 | The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to... |
| CVE-2025-6692 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all ... |
| CVE-2025-6681 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The Fan Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now