2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71389 | CRITICAL | 10 | 0.9% | Jul 23, 2026 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a versio... |
| CVE-2025-68081 | MEDIUM | 5.9 | — | Jul 23, 2026 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. |
| CVE-2025-60835 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. |
| CVE-2025-50330 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute... |
| CVE-2025-50329 | CRITICAL | 9.8 | 0.3% | Jul 22, 2026 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec... |
| CVE-2025-50327 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbi... |
| CVE-2025-50325 | MEDIUM | 5.4 | 0.3% | Jul 22, 2026 | BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa... |
| CVE-2025-50324 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneComman... |
| CVE-2025-44090 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted... |
| CVE-2025-44089 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a cr... |
| CVE-2025-13146 | MEDIUM | 6.5 | — | Jul 22, 2026 | The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a... |
| CVE-2025-68640 | MEDIUM | 5.3 | 0.3% | Jul 21, 2026 | The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T... |
| CVE-2025-66390 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) ... |
| CVE-2025-71398 | MEDIUM | 5.8 | 0.2% | Jul 18, 2026 | SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-n... |
| CVE-2025-71397 | HIGH | 7.1 | 0.3% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi... |
| CVE-2025-71396 | LOW | 2.3 | 0.3% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em... |
| CVE-2025-71395 | HIGH | 7.1 | 0.2% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to ... |
| CVE-2025-71394 | LOW | 2.3 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut... |
| CVE-2025-71393 | MEDIUM | 6 | 0.2% | Jul 18, 2026 | SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e... |
| CVE-2025-71392 | CRITICAL | 9.4 | 0.2% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the... |
| CVE-2025-71391 | HIGH | 7.1 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated ... |
| CVE-2025-71390 | MEDIUM | 5.8 | 0.2% | Jul 18, 2026 | SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames agains... |
| CVE-2025-51678 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to une... |
| CVE-2025-51677 | CRITICAL | 9.1 | 0.4% | Jul 17, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12... |
| CVE-2025-59866 | LOW | 3.3 | — | Jul 17, 2026 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now