2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-45769 | MEDIUM | 6.5 | 0.1% | Jul 31, 2025 | php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key leng... |
| CVE-2025-37112 | MEDIUM | 6 | 0.1% | Jul 31, 2025 | A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Functi... |
| CVE-2025-37111 | MEDIUM | 6 | 0.1% | Jul 31, 2025 | A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Fu... |
| CVE-2025-37110 | MEDIUM | 6 | 0.1% | Jul 31, 2025 | A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Tel... |
| CVE-2025-37109 | LOW | 3.5 | 0.2% | Jul 31, 2025 | Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product |
| CVE-2025-37108 | LOW | 3.5 | 0.2% | Jul 31, 2025 | Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product |
| CVE-2025-26064 | HIGH | 7.3 | 0.9% | Jul 31, 2025 | A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb... |
| CVE-2025-26063 | CRITICAL | 9.8 | 1.2% | Jul 31, 2025 | An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via in... |
| CVE-2025-26062 | CRITICAL | 9.8 | 1.0% | Jul 31, 2025 | An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the rou... |
| CVE-2025-8426 | CRITICAL | 9.4 | 1.6% | Jul 31, 2025 | Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerabil... |
| CVE-2025-54834 | MEDIUM | 6.9 | 0.5% | Jul 31, 2025 | OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/... |
| CVE-2025-54833 | HIGH | 7.5 | 0.5% | Jul 31, 2025 | OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protec... |
| CVE-2025-54832 | MEDIUM | 5.3 | 0.3% | Jul 31, 2025 | OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of ... |
| CVE-2025-51503 | HIGH | 7.6 | 0.4% | Jul 31, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts int... |
| CVE-2025-51385 | LOW | 3.5 | 0.4% | Jul 31, 2025 | D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter. |
| CVE-2025-51384 | LOW | 3.5 | 0.3% | Jul 31, 2025 | D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter. |
| CVE-2025-51383 | LOW | 3.5 | 0.3% | Jul 31, 2025 | D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter. |
| CVE-2025-50866 | MEDIUM | 6.1 | 0.3% | Jul 31, 2025 | CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of t... |
| CVE-2025-8409 | CRITICAL | 9.8 | 0.4% | Jul 31, 2025 | A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. Affected by this vuln... |
| CVE-2025-52203 | HIGH | 7.6 | 0.3% | Jul 31, 2025 | A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability res... |
| CVE-2025-50867 | MEDIUM | 6.5 | 0.2% | Jul 31, 2025 | A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where th... |
| CVE-2025-50850 | HIGH | 8.6 | 0.2% | Jul 31, 2025 | An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such a... |
| CVE-2025-50848 | MEDIUM | 6.1 | 0.2% | Jul 31, 2025 | A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3... |
| CVE-2025-50847 | MEDIUM | 6.5 | 0.1% | Jul 31, 2025 | Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparis... |
| CVE-2025-46809 | MEDIUM | 6.9 | 0.2% | Jul 31, 2025 | A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. Thi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now