2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-29556 | HIGH | 7.3 | 0.3% | Jul 31, 2025 | ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions... |
| CVE-2025-8408 | CRITICAL | 9.8 | 0.5% | Jul 31, 2025 | A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. Affected is an unk... |
| CVE-2025-52289 | HIGH | 8 | 0.4% | Jul 31, 2025 | A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileg... |
| CVE-2025-51569 | MEDIUM | 6.1 | 0.2% | Jul 31, 2025 | A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. Th... |
| CVE-2025-50849 | HIGH | 8 | 0.3% | Jul 31, 2025 | CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling ... |
| CVE-2025-50475 | CRITICAL | 9.8 | 7.9% | Jul 31, 2025 | An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated a... |
| CVE-2025-50270 | MEDIUM | 6.1 | 0.3% | Jul 31, 2025 | A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remot... |
| CVE-2025-34146 | HIGH | 7 | 0.2% | Jul 31, 2025 | A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitra... |
| CVE-2025-29557 | MEDIUM | 5.4 | 0.2% | Jul 31, 2025 | ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where user... |
| CVE-2025-8407 | CRITICAL | 9.8 | 0.4% | Jul 31, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Vehicle Management 1.0. This issue af... |
| CVE-2025-7738 | MEDIUM | 4.4 | 0.2% | Jul 31, 2025 | A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub... |
| CVE-2025-54589 | MEDIUM | 6.1 | 2.3% | Jul 31, 2025 | Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, use... |
| CVE-2025-8213 | HIGH | 7.2 | 0.5% | Jul 31, 2025 | The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien... |
| CVE-2025-8401 | MEDIUM | 4.3 | 0.3% | Jul 31, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
| CVE-2025-8382 | HIGH | 8.8 | 0.4% | Jul 31, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Online Hotel Reservation System 1.0. Affected ... |
| CVE-2025-8381 | HIGH | 8.8 | 0.4% | Jul 31, 2025 | A vulnerability, which was classified as critical, has been found in Campcodes Online Hotel Reservation System 1.0. This... |
| CVE-2025-8151 | MEDIUM | 4.3 | 0.4% | Jul 31, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, ... |
| CVE-2025-8068 | MEDIUM | 4.3 | 0.3% | Jul 31, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of ... |
| CVE-2025-8380 | MEDIUM | 5.4 | 0.3% | Jul 31, 2025 | A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability... |
| CVE-2025-8379 | HIGH | 7.2 | 0.5% | Jul 31, 2025 | A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an ... |
| CVE-2025-8378 | CRITICAL | 9.8 | 0.5% | Jul 31, 2025 | A vulnerability was found in Campcodes Online Hotel Reservation System 1.0. It has been rated as critical. Affected by t... |
| CVE-2025-8376 | CRITICAL | 9.8 | 0.5% | Jul 31, 2025 | A vulnerability classified as critical has been found in code-projects Vehicle Management 1.0. Affected is an unknown fu... |
| CVE-2025-41688 | HIGH | 7.2 | 0.6% | Jul 31, 2025 | A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the ... |
| CVE-2025-40980 | MEDIUM | 5.1 | 0.5% | Jul 31, 2025 | A Stored Cross Site Scripting vulnerability has been found in UltimatePOS by UltimateFosters. This vulnerability is due ... |
| CVE-2025-2813 | HIGH | 7.5 | 0.6% | Jul 31, 2025 | An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http servi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now