2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43977 | MEDIUM | 5.5 | 0.1% | Jul 21, 2025 | The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) t... |
| CVE-2025-43976 | MEDIUM | 5.5 | 0.2% | Jul 21, 2025 | The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no p... |
| CVE-2025-7926 | MEDIUM | 5.4 | 0.3% | Jul 21, 2025 | A vulnerability, which was classified as problematic, was found in PHPGurukul Online Banquet Booking System 1.0. This af... |
| CVE-2025-6235 | MEDIUM | 6.1 | 0.2% | Jul 21, 2025 | In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the ... |
| CVE-2025-7925 | MEDIUM | 6.1 | 0.5% | Jul 21, 2025 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Banquet Booking System 1.0. Af... |
| CVE-2025-41100 | MEDIUM | 5.9 | 0.2% | Jul 21, 2025 | Incorrect authentication vulnerability in ParkingDoor. Through this vulnerability it is possible to operate the device w... |
| CVE-2025-2301 | MEDIUM | 4.4 | 0.3% | Jul 21, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploit... |
| CVE-2025-7924 | MEDIUM | 5.4 | 0.3% | Jul 21, 2025 | A vulnerability classified as problematic was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vu... |
| CVE-2025-5681 | MEDIUM | 6.5 | 0.3% | Jul 21, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted ... |
| CVE-2025-41458 | MEDIUM | 5.5 | 0.1% | Jul 21, 2025 | Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive... |
| CVE-2025-41681 | MEDIUM | 4.8 | 0.3% | Jul 21, 2025 | A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special el... |
| CVE-2025-41677 | MEDIUM | 4.9 | 0.6% | Jul 21, 2025 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to... |
| CVE-2025-41676 | MEDIUM | 4.9 | 0.5% | Jul 21, 2025 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to... |
| CVE-2025-7369 | MEDIUM | 6.1 | 0.2% | Jul 21, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v... |
| CVE-2025-7354 | MEDIUM | 6.4 | 0.3% | Jul 21, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-4685 | MEDIUM | 6.4 | 0.2% | Jul 21, 2025 | The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-4570 | MEDIUM | 6.9 | 0.4% | Jul 21, 2025 | An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token t... |
| CVE-2025-7920 | MEDIUM | 6.1 | 0.3% | Jul 21, 2025 | WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unau... |
| CVE-2025-0664 | MEDIUM | 6.7 | 0.2% | Jul 21, 2025 | A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent... |
| CVE-2025-53771 | MEDIUM | 6.5 | 99.9% | Jul 20, 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ... |
| CVE-2025-7907 | MEDIUM | 4.3 | 0.4% | Jul 20, 2025 | A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unkn... |
| CVE-2025-54319 | MEDIUM | 6.3 | 0.3% | Jul 20, 2025 | An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized acces... |
| CVE-2025-7906 | MEDIUM | 5.4 | 0.3% | Jul 20, 2025 | A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function... |
| CVE-2025-54316 | MEDIUM | 4.9 | 0.2% | Jul 20, 2025 | An issue was discovered in Logpoint before 7.6.0. When creating reports, attackers can create custom Jinja templates tha... |
| CVE-2025-7903 | MEDIUM | 5.4 | 0.2% | Jul 20, 2025 | A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now