2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26400 | MEDIUM | 6.5 | 0.2% | Jul 29, 2025 | SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could ... |
| CVE-2025-53649 | MEDIUM | 5.9 | 0.1% | Jul 29, 2025 | "SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V... |
| CVE-2025-53080 | MEDIUM | 6.5 | 0.3% | Jul 29, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) al... |
| CVE-2025-53079 | MEDIUM | 4.9 | 0.4% | Jul 29, 2025 | Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sen... |
| CVE-2025-53077 | MEDIUM | 6.5 | 0.3% | Jul 29, 2025 | An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without... |
| CVE-2025-4566 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2025-4370 | MEDIUM | 5.3 | 0.3% | Jul 29, 2025 | The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on proc... |
| CVE-2025-3075 | MEDIUM | 5.4 | 0.2% | Jul 29, 2025 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2025-7811 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2025-7810 | MEDIUM | 5.4 | 0.2% | Jul 29, 2025 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'd... |
| CVE-2025-7809 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2025-54768 | MEDIUM | 5.3 | 3.9% | Jul 29, 2025 | An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ... |
| CVE-2025-54767 | MEDIUM | 6.5 | 5.3% | Jul 29, 2025 | An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd... |
| CVE-2025-54766 | MEDIUM | 5.3 | 6.8% | Jul 29, 2025 | An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ... |
| CVE-2025-54765 | MEDIUM | 5.3 | 6.8% | Jul 29, 2025 | An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ... |
| CVE-2025-54429 | MEDIUM | 6.9 | 0.5% | Jul 28, 2025 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account addre... |
| CVE-2025-54427 | MEDIUM | 6.9 | 0.5% | Jul 28, 2025 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_pric... |
| CVE-2025-54423 | MEDIUM | 6.1 | 0.4% | Jul 28, 2025 | copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is abl... |
| CVE-2025-7676 | MEDIUM | 5.4 | 0.1% | Jul 28, 2025 | DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute... |
| CVE-2025-54538 | MEDIUM | 5.5 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command |
| CVE-2025-54537 | MEDIUM | 5.5 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots |
| CVE-2025-54534 | MEDIUM | 4.8 | 0.7% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page |
| CVE-2025-54533 | MEDIUM | 4.3 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration |
| CVE-2025-54532 | MEDIUM | 4.3 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependenc... |
| CVE-2025-54527 | MEDIUM | 6.1 | 0.2% | Jul 28, 2025 | In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now