2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54365 | HIGH | 7.5 | 0.7% | Jul 23, 2025 | fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetratio... |
| CVE-2025-54377 | HIGH | 7.8 | 1.1% | Jul 23, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode d... |
| CVE-2025-54371 | — | — | — | Jul 23, 2025 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2025-53942 | HIGH | 7.4 | 0.5% | Jul 23, 2025 | authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set o... |
| CVE-2025-53537 | HIGH | 7.5 | 0.4% | Jul 23, 2025 | LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, t... |
| CVE-2025-47281 | HIGH | 7.7 | 0.5% | Jul 23, 2025 | Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial ... |
| CVE-2025-32019 | MEDIUM | 4.1 | 0.3% | Jul 23, 2025 | Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 an... |
| CVE-2025-8058 | MEDIUM | 5.9 | 0.2% | Jul 23, 2025 | The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocat... |
| CVE-2025-44109 | MEDIUM | 5.4 | 0.2% | Jul 23, 2025 | A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages. |
| CVE-2025-50477 | MEDIUM | 5.4 | 0.3% | Jul 23, 2025 | A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages. |
| CVE-2025-47187 | HIGH | 7.5 | 0.9% | Jul 23, 2025 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th... |
| CVE-2025-46686 | LOW | 3.5 | 0.3% | Jul 23, 2025 | Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated ... |
| CVE-2025-4700 | MEDIUM | 6.1 | 0.2% | Jul 23, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18... |
| CVE-2025-4439 | MEDIUM | 5.4 | 0.2% | Jul 23, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18... |
| CVE-2025-8069 | HIGH | 7.8 | 0.2% | Jul 23, 2025 | During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\window... |
| CVE-2025-50481 | MEDIUM | 4.8 | 0.6% | Jul 23, 2025 | A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers ... |
| CVE-2025-46171 | MEDIUM | 5.4 | 0.3% | Jul 23, 2025 | vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticat... |
| CVE-2025-2634 | HIGH | 7.8 | 0.2% | Jul 23, 2025 | Out of bounds read vulnerability due to improper bounds checking in NI LabVIEW in fontmgr may result in information disc... |
| CVE-2025-2633 | HIGH | 7.8 | 0.2% | Jul 23, 2025 | Out of bounds read vulnerability due to improper bounds checking in NI LabVIEW in lvre!UDecStrToNum that may result in i... |
| CVE-2025-6018 | HIGH | 7.8 | 1.0% | Jul 23, 2025 | A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication... |
| CVE-2025-40598 | MEDIUM | 6.1 | 53.2% | Jul 23, 2025 | A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauth... |
| CVE-2025-40597 | HIGH | 7.5 | 27.6% | Jul 23, 2025 | A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to... |
| CVE-2025-40596 | HIGH | 7.3 | 56.1% | Jul 23, 2025 | A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker t... |
| CVE-2025-36117 | MEDIUM | 6.3 | 0.2% | Jul 23, 2025 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated use... |
| CVE-2025-36116 | MEDIUM | 6.3 | 0.2% | Jul 23, 2025 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a sp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now