2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54767 | MEDIUM | 6.5 | 5.3% | Jul 29, 2025 | An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd... |
| CVE-2025-54766 | MEDIUM | 5.3 | 6.8% | Jul 29, 2025 | An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ... |
| CVE-2025-54765 | MEDIUM | 5.3 | 6.8% | Jul 29, 2025 | An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ... |
| CVE-2025-54429 | MEDIUM | 6.9 | 0.5% | Jul 28, 2025 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account addre... |
| CVE-2025-54428 | CRITICAL | 9.8 | 0.5% | Jul 28, 2025 | RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessibl... |
| CVE-2025-54427 | MEDIUM | 6.9 | 0.5% | Jul 28, 2025 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_pric... |
| CVE-2025-54426 | CRITICAL | 9.9 | 0.3% | Jul 28, 2025 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f... |
| CVE-2025-54423 | MEDIUM | 6.1 | 0.4% | Jul 28, 2025 | copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is abl... |
| CVE-2025-54419 | CRITICAL | 10 | 0.4% | Jul 28, 2025 | A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from t... |
| CVE-2025-50486 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allo... |
| CVE-2025-50485 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 al... |
| CVE-2025-29534 | HIGH | 8.8 | 0.7% | Jul 28, 2025 | An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker ... |
| CVE-2025-8283 | LOW | 3.7 | 0.3% | Jul 28, 2025 | A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman se... |
| CVE-2025-8194 | HIGH | 7.5 | 0.6% | Jul 28, 2025 | There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar... |
| CVE-2025-50487 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management Sy... |
| CVE-2025-50484 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to... |
| CVE-2025-54299 | CRITICAL | 9.4 | 0.4% | Jul 28, 2025 | A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered. |
| CVE-2025-54298 | CRITICAL | 9.4 | 0.4% | Jul 28, 2025 | A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered. |
| CVE-2025-50492 | HIGH | 7.5 | 0.5% | Jul 28, 2025 | Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allo... |
| CVE-2025-50491 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v... |
| CVE-2025-50489 | HIGH | 7.5 | 0.5% | Jul 28, 2025 | Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System ... |
| CVE-2025-50488 | HIGH | 7.1 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management Syst... |
| CVE-2025-43023 | CRITICAL | 9.1 | 0.2% | Jul 28, 2025 | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This... |
| CVE-2025-7676 | MEDIUM | 5.4 | 0.1% | Jul 28, 2025 | DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute... |
| CVE-2025-54538 | MEDIUM | 5.5 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now