2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6753 | MEDIUM | 6.3 | 0.2% | Jun 27, 2025 | A vulnerability was found in huija bicycleSharingServer 1.0 and classified as critical. This issue affects the function ... |
| CVE-2025-6488 | MEDIUM | 6.4 | 0.2% | Jun 27, 2025 | The isMobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ parameter in all version... |
| CVE-2025-45737 | MEDIUM | 6.5 | 0.3% | Jun 27, 2025 | An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privilege... |
| CVE-2025-47823 | MEDIUM | 4.6 | 0.2% | Jun 27, 2025 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system. |
| CVE-2025-47822 | MEDIUM | 6.8 | 0.2% | Jun 27, 2025 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper ... |
| CVE-2025-47821 | MEDIUM | 4.6 | 0.2% | Jun 27, 2025 | Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system. |
| CVE-2025-6749 | MEDIUM | 6.3 | 0.2% | Jun 27, 2025 | A vulnerability classified as critical was found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac... |
| CVE-2025-47819 | MEDIUM | 6.8 | 0.2% | Jun 27, 2025 | Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control. |
| CVE-2025-47818 | MEDIUM | 4.6 | 0.2% | Jun 27, 2025 | Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection. |
| CVE-2025-6738 | MEDIUM | 6.3 | 0.2% | Jun 27, 2025 | A vulnerability, which was classified as critical, has been found in huija bicycleSharingServer up to 7b8a3ba48ad618604a... |
| CVE-2025-6731 | MEDIUM | 6.3 | 0.3% | Jun 26, 2025 | A vulnerability was found in yzcheng90 X-SpringBoot up to 5.0 and classified as critical. Affected by this issue is the ... |
| CVE-2025-5731 | MEDIUM | 5.5 | 0.1% | Jun 26, 2025 | A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed ... |
| CVE-2025-52555 | MEDIUM | 6.5 | 0.2% | Jun 26, 2025 | Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 th... |
| CVE-2025-5995 | MEDIUM | 4.6 | 0.2% | Jun 26, 2025 | Canon EOS Webcam Utility Pro for MAC OS version 2.3d (2.3.29) and earlier contains an improper directory permissions vul... |
| CVE-2025-53122 | MEDIUM | 6.9 | 0.2% | Jun 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon an... |
| CVE-2025-49592 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. A... |
| CVE-2025-53121 | MEDIUM | 6.9 | 0.2% | Jun 26, 2025 | Multiple stored XSS were found on different nodes with unsanitized parameters in OpenMNS Horizon 33.0.8 and versions ear... |
| CVE-2025-53013 | MEDIUM | 5.2 | 0.2% | Jun 26, 2025 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9... |
| CVE-2025-6702 | MEDIUM | 5.3 | 0.3% | Jun 26, 2025 | A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown fun... |
| CVE-2025-6701 | MEDIUM | 6.1 | 0.3% | Jun 26, 2025 | A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This issue affects some u... |
| CVE-2025-6700 | MEDIUM | 6.1 | 0.4% | Jun 26, 2025 | A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of... |
| CVE-2025-6699 | MEDIUM | 4.1 | 0.3% | Jun 26, 2025 | A vulnerability classified as problematic has been found in LabRedesCefetRJ WeGIA 3.4.0. This affects an unknown part of... |
| CVE-2025-51671 | MEDIUM | 5.4 | 0.3% | Jun 26, 2025 | A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability ... |
| CVE-2025-50350 | MEDIUM | 5.4 | 0.5% | Jun 26, 2025 | PHPGurukul Pre-School Enrollment System Project v1.0 is vulnerable to Directory Traversal in manage-classes.php. |
| CVE-2025-44141 | MEDIUM | 6.1 | 0.2% | Jun 26, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now