2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7798 | MEDIUM | 6.3 | 0.2% | Jul 18, 2025 | A vulnerability classified as critical has been found in Beijing Shenzhou Shihan Technology Multimedia Integrated Busine... |
| CVE-2025-52163 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v... |
| CVE-2025-33014 | MEDIUM | 6.1 | 0.2% | Jul 18, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web... |
| CVE-2025-7797 | MEDIUM | 5.5 | 0.9% | Jul 18, 2025 | A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf... |
| CVE-2025-52168 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 all... |
| CVE-2025-52166 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate... |
| CVE-2025-52162 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the ... |
| CVE-2025-50586 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF). |
| CVE-2025-45157 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users. |
| CVE-2025-45156 | MEDIUM | 5.3 | 0.4% | Jul 18, 2025 | Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users. |
| CVE-2025-7791 | MEDIUM | 5.4 | 0.2% | Jul 18, 2025 | A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declared as problematic. T... |
| CVE-2025-7790 | MEDIUM | 6.5 | 0.8% | Jul 18, 2025 | A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part... |
| CVE-2025-54078 | MEDIUM | 6.1 | 0.2% | Jul 18, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-54077 | MEDIUM | 6.1 | 0.2% | Jul 18, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-54076 | MEDIUM | 6.1 | 0.2% | Jul 18, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-54059 | MEDIUM | 4.4 | 0.1% | Jul 18, 2025 | melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version ... |
| CVE-2025-46732 | MEDIUM | 5.4 | 0.2% | Jul 18, 2025 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2025-46000 | MEDIUM | 6.5 | 0.4% | Jul 18, 2025 | An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2... |
| CVE-2025-7786 | MEDIUM | 5.4 | 0.2% | Jul 18, 2025 | A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects som... |
| CVE-2025-7784 | MEDIUM | 6.5 | 0.4% | Jul 18, 2025 | A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are e... |
| CVE-2025-46002 | MEDIUM | 6.5 | 1.6% | Jul 18, 2025 | An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP re... |
| CVE-2025-7785 | MEDIUM | 4.3 | 0.4% | Jul 18, 2025 | A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the fun... |
| CVE-2025-6233 | MEDIUM | 4.9 | 0.4% | Jul 18, 2025 | Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths... |
| CVE-2025-50126 | MEDIUM | 5.3 | 0.3% | Jul 18, 2025 | A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authent... |
| CVE-2025-50058 | MEDIUM | 5.1 | 0.4% | Jul 18, 2025 | A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote auth... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now