2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54129 | MEDIUM | 4.3 | 0.3% | Jul 21, 2025 | HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versio... |
| CVE-2025-54128 | MEDIUM | 6.1 | 0.2% | Jul 21, 2025 | HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the ... |
| CVE-2025-7938 | MEDIUM | 4.3 | 0.3% | Jul 21, 2025 | A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the ... |
| CVE-2025-7233 | MEDIUM | 5.5 | 0.2% | Jul 21, 2025 | IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability a... |
| CVE-2025-54121 | MEDIUM | 5.3 | 0.5% | Jul 21, 2025 | Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async w... |
| CVE-2025-51403 | MEDIUM | 6.5 | 1.5% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.... |
| CVE-2025-51401 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attacke... |
| CVE-2025-51400 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attac... |
| CVE-2025-51398 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows att... |
| CVE-2025-51397 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers... |
| CVE-2025-51396 | MEDIUM | 5.4 | 0.9% | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web sc... |
| CVE-2025-36057 | MEDIUM | 4.6 | 0.2% | Jul 21, 2025 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authe... |
| CVE-2025-52575 | MEDIUM | 6.5 | 0.7% | Jul 21, 2025 | EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulner... |
| CVE-2025-7716 | MEDIUM | 6.1 | 0.2% | Jul 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time S... |
| CVE-2025-7715 | MEDIUM | 6.1 | 0.2% | Jul 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Attri... |
| CVE-2025-7392 | MEDIUM | 6.1 | 0.2% | Jul 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookies Add... |
| CVE-2025-43720 | MEDIUM | 6.5 | 0.4% | Jul 21, 2025 | Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is ex... |
| CVE-2025-36603 | MEDIUM | 4.8 | 0.1% | Jul 21, 2025 | Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low... |
| CVE-2025-32744 | MEDIUM | 6.6 | 0.4% | Jul 21, 2025 | Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high priv... |
| CVE-2025-30477 | MEDIUM | 4.9 | 0.2% | Jul 21, 2025 | Dell PowerScale OneFS, versions prior to 9.11.0.0, contains a use of a broken or risky cryptographic algorithm vulnerabi... |
| CVE-2025-52374 | MEDIUM | 4.6 | 0.2% | Jul 21, 2025 | Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passw... |
| CVE-2025-52373 | MEDIUM | 4.6 | 0.3% | Jul 21, 2025 | Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwo... |
| CVE-2025-52372 | MEDIUM | 5.1 | 0.2% | Jul 21, 2025 | An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation... |
| CVE-2025-46119 | MEDIUM | 6.3 | 0.3% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDir... |
| CVE-2025-46118 | MEDIUM | 5.3 | 0.5% | Jul 21, 2025 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDire... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now