2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54537 | MEDIUM | 5.5 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots |
| CVE-2025-54536 | HIGH | 8.8 | 0.1% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint |
| CVE-2025-54535 | HIGH | 7.5 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms |
| CVE-2025-54534 | MEDIUM | 4.8 | 0.7% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page |
| CVE-2025-54533 | MEDIUM | 4.3 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration |
| CVE-2025-54532 | MEDIUM | 4.3 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependenc... |
| CVE-2025-54531 | CRITICAL | 9.4 | 0.3% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows |
| CVE-2025-54530 | CRITICAL | 9.8 | 0.2% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions |
| CVE-2025-54529 | HIGH | 7.5 | 0.1% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration |
| CVE-2025-54528 | HIGH | 8.8 | 0.1% | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow |
| CVE-2025-54527 | MEDIUM | 6.1 | 0.2% | Jul 28, 2025 | In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in ... |
| CVE-2025-50494 | HIGH | 7.5 | 0.4% | Jul 28, 2025 | Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v... |
| CVE-2025-50493 | HIGH | 7.5 | 0.3% | Jul 28, 2025 | Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management S... |
| CVE-2025-50490 | HIGH | 7.5 | 0.4% | Jul 28, 2025 | Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management Syst... |
| CVE-2025-6250 | MEDIUM | 6.7 | 0.2% | Jul 28, 2025 | Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypass... |
| CVE-2025-2297 | HIGH | 7.8 | 0.1% | Jul 28, 2025 | Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challe... |
| CVE-2025-54418 | CRITICAL | 9.8 | 1.5% | Jul 28, 2025 | CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affe... |
| CVE-2025-53696 | CRITICAL | 9.3 | 0.1% | Jul 28, 2025 | iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the ... |
| CVE-2025-30125 | CRITICAL | 9.8 | 0.4% | Jul 28, 2025 | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default crede... |
| CVE-2025-8279 | CRITICAL | 9.8 | 0.4% | Jul 28, 2025 | Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query... |
| CVE-2025-53695 | CRITICAL | 9.4 | 0.9% | Jul 28, 2025 | OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileg... |
| CVE-2025-32731 | MEDIUM | 6.1 | 0.7% | Jul 28, 2025 | A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality of meddream Med... |
| CVE-2025-30133 | CRITICAL | 9.8 | 0.5% | Jul 28, 2025 | An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires devic... |
| CVE-2025-30126 | MEDIUM | 5.3 | 0.3% | Jul 28, 2025 | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a phy... |
| CVE-2025-30124 | CRITICAL | 9.8 | 0.3% | Jul 28, 2025 | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now