2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65341 | MEDIUM | 6.1 | 0.1% | Jul 30, 2026 | Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. |
| CVE-2025-51684 | MEDIUM | 6.1 | 0.2% | Jul 30, 2026 | CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data ... |
| CVE-2025-36374 | MEDIUM | 5.5 | — | Jul 30, 2026 | IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile... |
| CVE-2025-0152 | MEDIUM | 6.1 | 0.2% | Jul 30, 2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1... |
| CVE-2025-36431 | MEDIUM | 5.4 | 0.2% | Jul 30, 2026 | IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera... |
| CVE-2025-36298 | MEDIUM | 5.4 | 0.2% | Jul 30, 2026 | IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0... |
| CVE-2025-65337 | MEDIUM | 6.1 | 0.1% | Jul 29, 2026 | Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address ... |
| CVE-2025-59181 | MEDIUM | 4.8 | 0.3% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio... |
| CVE-2025-59180 | MEDIUM | 5.1 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm s... |
| CVE-2025-59178 | MEDIUM | 4.8 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera... |
| CVE-2025-59177 | MEDIUM | 6.8 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowi... |
| CVE-2025-9205 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.... |
| CVE-2025-68081 | MEDIUM | 5.9 | — | Jul 23, 2026 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. |
| CVE-2025-50325 | MEDIUM | 5.4 | 0.3% | Jul 22, 2026 | BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa... |
| CVE-2025-13146 | MEDIUM | 6.5 | 0.5% | Jul 22, 2026 | The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a... |
| CVE-2025-68640 | MEDIUM | 5.3 | 0.3% | Jul 21, 2026 | The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T... |
| CVE-2025-71397 | MEDIUM | 6.5 | 0.3% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi... |
| CVE-2025-71396 | MEDIUM | 6.5 | 0.3% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em... |
| CVE-2025-71395 | MEDIUM | 6.5 | 0.2% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to ... |
| CVE-2025-71394 | MEDIUM | 4.3 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut... |
| CVE-2025-71393 | MEDIUM | 6.5 | 0.2% | Jul 18, 2026 | SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e... |
| CVE-2025-71391 | MEDIUM | 6.5 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated ... |
| CVE-2025-45870 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet c... |
| CVE-2025-32781 | MEDIUM | 6.5 | — | Jul 15, 2026 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior... |
| CVE-2025-62826 | MEDIUM | 4.3 | 0.3% | Jul 14, 2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now