2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54379 | CRITICAL | 9.8 | 0.8% | Jul 24, 2025 | LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev... |
| CVE-2025-54369 | CRITICAL | 9.3 | 0.4% | Jul 24, 2025 | Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML lo... |
| CVE-2025-53940 | HIGH | 8.5 | 2.6% | Jul 24, 2025 | Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central serv... |
| CVE-2025-3614 | MEDIUM | 5.4 | 0.2% | Jul 24, 2025 | The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-32429 | CRITICAL | 9.8 | 85.4% | Jul 24, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4... |
| CVE-2025-22165 | HIGH | 7.3 | 0.1% | Jul 24, 2025 | This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac.... |
| CVE-2025-8123 | HIGH | 8.8 | 0.4% | Jul 24, 2025 | A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown fu... |
| CVE-2025-7404 | CRITICAL | 9.8 | 2.7% | Jul 24, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web,... |
| CVE-2025-6260 | CRITICAL | 9.8 | 0.5% | Jul 24, 2025 | The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated atta... |
| CVE-2025-31955 | MEDIUM | 6.5 | 0.3% | Jul 24, 2025 | HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensi... |
| CVE-2025-31953 | MEDIUM | 6.5 | 0.3% | Jul 24, 2025 | HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted ... |
| CVE-2025-31952 | HIGH | 7.1 | 0.3% | Jul 24, 2025 | HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless... |
| CVE-2025-6998 | HIGH | 8.7 | 0.8% | Jul 24, 2025 | ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remo... |
| CVE-2025-8115 | MEDIUM | 5.4 | 0.3% | Jul 24, 2025 | A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by... |
| CVE-2025-5039 | HIGH | 7.8 | 0.2% | Jul 24, 2025 | A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to exec... |
| CVE-2025-45702 | MEDIUM | 6.5 | 0.2% | Jul 24, 2025 | SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext. |
| CVE-2025-53084 | MEDIUM | 6.1 | 0.7% | Jul 24, 2025 | A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and... |
| CVE-2025-50128 | MEDIUM | 6.1 | 0.8% | Jul 24, 2025 | A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVide... |
| CVE-2025-48732 | CRITICAL | 9.8 | 1.1% | Jul 24, 2025 | An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially c... |
| CVE-2025-47061 | MEDIUM | 5.4 | 0.3% | Jul 24, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-46996 | MEDIUM | 5.4 | 0.3% | Jul 24, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-46993 | MEDIUM | 5.4 | 0.3% | Jul 24, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-46410 | MEDIUM | 6.1 | 0.8% | Jul 24, 2025 | A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality o... |
| CVE-2025-41420 | CRITICAL | 9.6 | 1.1% | Jul 24, 2025 | A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4... |
| CVE-2025-36548 | CRITICAL | 9.6 | 1.0% | Jul 24, 2025 | A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of W... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now