2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28170 | HIGH | 7.6 | 0.3% | Jul 29, 2025 | Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with direct... |
| CVE-2025-28171 | MEDIUM | 6.5 | 0.3% | Jul 29, 2025 | An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the ... |
| CVE-2025-51970 | HIGH | 7.7 | 0.2% | Jul 29, 2025 | A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 du... |
| CVE-2025-50738 | CRITICAL | 9.8 | 2.0% | Jul 29, 2025 | The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us... |
| CVE-2025-46059 | CRITICAL | 9.8 | 0.7% | Jul 29, 2025 | langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component.... |
| CVE-2025-28172 | MEDIUM | 6.5 | 0.3% | Jul 29, 2025 | Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Att... |
| CVE-2025-52358 | MEDIUM | 6.3 | 0.3% | Jul 29, 2025 | A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Lo... |
| CVE-2025-7458 | CRITICAL | 9.1 | 0.2% | Jul 29, 2025 | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attack... |
| CVE-2025-6505 | HIGH | 8.1 | 0.3% | Jul 29, 2025 | Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipe... |
| CVE-2025-6504 | HIGH | 8.4 | 0.2% | Jul 29, 2025 | In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-... |
| CVE-2025-6175 | HIGH | 7.2 | 0.2% | Jul 29, 2025 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Sp... |
| CVE-2025-6060 | MEDIUM | 5.4 | 0.2% | Jul 29, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Softwa... |
| CVE-2025-54422 | MEDIUM | 5.5 | 0.1% | Jul 29, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.... |
| CVE-2025-41241 | MEDIUM | 4.4 | 0.3% | Jul 29, 2025 | VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and ha... |
| CVE-2025-40686 | MEDIUM | 6.1 | 0.2% | Jul 29, 2025 | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ... |
| CVE-2025-40685 | MEDIUM | 6.1 | 0.2% | Jul 29, 2025 | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ... |
| CVE-2025-40684 | MEDIUM | 6.1 | 0.2% | Jul 29, 2025 | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ... |
| CVE-2025-40683 | MEDIUM | 6.1 | 0.2% | Jul 29, 2025 | Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ... |
| CVE-2025-40682 | CRITICAL | 9.8 | 0.3% | Jul 29, 2025 | SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, creat... |
| CVE-2025-5587 | MEDIUM | 6.4 | 0.3% | Jul 29, 2025 | The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in al... |
| CVE-2025-8216 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in a... |
| CVE-2025-8196 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cust... |
| CVE-2025-7689 | HIGH | 8.8 | 0.3% | Jul 29, 2025 | The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tf... |
| CVE-2025-6730 | MEDIUM | 4.3 | 0.2% | Jul 29, 2025 | The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to... |
| CVE-2025-6692 | MEDIUM | 6.4 | 0.2% | Jul 29, 2025 | The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now