2025 CVE Vulnerabilities
45,347 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53889 | MEDIUM | 6.5 | 0.4% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to... |
| CVE-2025-53887 | MEDIUM | 5.3 | 0.5% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ... |
| CVE-2025-53886 | MEDIUM | 4.5 | 0.4% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ... |
| CVE-2025-53885 | MEDIUM | 4.2 | 0.2% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ... |
| CVE-2025-53839 | MEDIUM | 4 | 0.2% | Jul 15, 2025 | DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interfac... |
| CVE-2025-53834 | MEDIUM | 6.3 | 0.2% | Jul 14, 2025 | Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s... |
| CVE-2025-53824 | MEDIUM | 5.4 | 0.2% | Jul 14, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-53822 | MEDIUM | 6.1 | 0.2% | Jul 14, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-53821 | MEDIUM | 6.1 | 0.2% | Jul 14, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirec... |
| CVE-2025-53820 | MEDIUM | 6.1 | 0.2% | Jul 14, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-53640 | MEDIUM | 6.5 | 0.6% | Jul 14, 2025 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Startin... |
| CVE-2025-52363 | MEDIUM | 6.8 | 0.2% | Jul 14, 2025 | Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An a... |
| CVE-2025-7625 | MEDIUM | 4.3 | 0.5% | Jul 14, 2025 | A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b9... |
| CVE-2025-51660 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php. |
| CVE-2025-51659 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php. |
| CVE-2025-51658 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php. |
| CVE-2025-51657 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php. |
| CVE-2025-51656 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php. |
| CVE-2025-51655 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php. |
| CVE-2025-51654 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php. |
| CVE-2025-51653 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php. |
| CVE-2025-51652 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php. |
| CVE-2025-51651 | MEDIUM | 5.5 | 0.2% | Jul 14, 2025 | An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attack... |
| CVE-2025-51650 | MEDIUM | 5.6 | 0.3% | Jul 14, 2025 | An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to ... |
| CVE-2025-7519 | MEDIUM | 6.7 | 0.2% | Jul 14, 2025 | A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds wri... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now