2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51651 | MEDIUM | 5.5 | 0.2% | Jul 14, 2025 | An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attack... |
| CVE-2025-51650 | MEDIUM | 5.6 | 0.3% | Jul 14, 2025 | An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to ... |
| CVE-2025-7519 | MEDIUM | 6.7 | 0.2% | Jul 14, 2025 | A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds wri... |
| CVE-2025-7601 | MEDIUM | 5.4 | 0.2% | Jul 14, 2025 | A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vu... |
| CVE-2025-7618 | MEDIUM | 4.8 | 0.3% | Jul 14, 2025 | A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. A... |
| CVE-2025-24391 | MEDIUM | 5.3 | 0.2% | Jul 14, 2025 | A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts th... |
| CVE-2025-7579 | MEDIUM | 4.3 | 0.3% | Jul 14, 2025 | A vulnerability was found in chinese-poetry 0.1. It has been rated as problematic. This issue affects some unknown proce... |
| CVE-2025-7578 | MEDIUM | 5 | 2.0% | Jul 14, 2025 | A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been declared as critical.... |
| CVE-2025-7575 | MEDIUM | 5.1 | 0.4% | Jul 14, 2025 | A vulnerability has been found in Zavy86 WikiDocs up to 1.0.77 and classified as critical. Affected by this vulnerabilit... |
| CVE-2025-7380 | MEDIUM | 4.8 | 0.3% | Jul 14, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM, the issue allows an attacker to i... |
| CVE-2025-7573 | MEDIUM | 5.5 | 0.3% | Jul 14, 2025 | A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1... |
| CVE-2025-7572 | MEDIUM | 5.5 | 0.3% | Jul 14, 2025 | A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P a... |
| CVE-2025-29606 | MEDIUM | 4.3 | 0.3% | Jul 14, 2025 | py-libp2p before 0.2.3 allows a peer to cause a denial of service (resource consumption) via a large RSA key. |
| CVE-2025-7567 | MEDIUM | 4.3 | 0.3% | Jul 14, 2025 | A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processin... |
| CVE-2025-7552 | MEDIUM | 6.3 | 0.3% | Jul 14, 2025 | A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the... |
| CVE-2025-1220 | MEDIUM | 5.3 | 0.5% | Jul 13, 2025 | In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like f... |
| CVE-2025-6491 | MEDIUM | 5.9 | 0.9% | Jul 13, 2025 | In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data... |
| CVE-2025-53865 | MEDIUM | 6.4 | 0.2% | Jul 13, 2025 | In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive). |
| CVE-2025-7511 | MEDIUM | 6.5 | 0.3% | Jul 13, 2025 | A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown p... |
| CVE-2025-7488 | MEDIUM | 4.3 | 0.4% | Jul 12, 2025 | A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and cl... |
| CVE-2025-7487 | MEDIUM | 6.3 | 0.2% | Jul 12, 2025 | A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f71... |
| CVE-2025-7485 | MEDIUM | 4.8 | 0.2% | Jul 12, 2025 | A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the functi... |
| CVE-2025-36104 | MEDIUM | 6.5 | 0.2% | Jul 12, 2025 | IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due t... |
| CVE-2025-7518 | MEDIUM | 4.9 | 0.4% | Jul 12, 2025 | The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via th... |
| CVE-2025-7464 | MEDIUM | 6.3 | 0.4% | Jul 12, 2025 | A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now