2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31513 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the Is... |
| CVE-2025-31512 | HIGH | 7.3 | 0.4% | Jul 22, 2025 | An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover ... |
| CVE-2025-31511 | HIGH | 7.3 | 0.4% | Jul 22, 2025 | An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user I... |
| CVE-2025-51479 | MEDIUM | 5.4 | 0.3% | Jul 22, 2025 | Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated att... |
| CVE-2025-51471 | MEDIUM | 6.9 | 3.8% | Jul 22, 2025 | Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authen... |
| CVE-2025-51459 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers t... |
| CVE-2025-51464 | HIGH | 8.8 | 0.6% | Jul 22, 2025 | Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims bro... |
| CVE-2025-48964 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data co... |
| CVE-2025-6741 | HIGH | 7.7 | 0.4% | Jul 22, 2025 | Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthor... |
| CVE-2025-6523 | CRITICAL | 9.5 | 0.4% | Jul 22, 2025 | Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker t... |
| CVE-2025-51482 | HIGH | 8.8 | 1.9% | Jul 22, 2025 | Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem... |
| CVE-2025-51481 | MEDIUM | 6.6 | 0.5% | Jul 22, 2025 | Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC... |
| CVE-2025-8019 | HIGH | 8.8 | 0.8% | Jul 22, 2025 | A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected ... |
| CVE-2025-7371 | MEDIUM | 6.8 | 0.3% | Jul 22, 2025 | Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vu... |
| CVE-2025-5042 | HIGH | 7.8 | 0.2% | Jul 22, 2025 | A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A mal... |
| CVE-2025-51480 | HIGH | 8.8 | 0.6% | Jul 22, 2025 | Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrit... |
| CVE-2025-51463 | HIGH | 7 | 0.5% | Jul 22, 2025 | Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's fi... |
| CVE-2025-48498 | HIGH | 7.5 | 0.6% | Jul 22, 2025 | A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when pr... |
| CVE-2025-46354 | HIGH | 7.5 | 0.9% | Jul 22, 2025 | A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomber... |
| CVE-2025-36520 | HIGH | 7.5 | 0.9% | Jul 22, 2025 | A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg... |
| CVE-2025-36512 | HIGH | 7.5 | 0.5% | Jul 22, 2025 | A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction he... |
| CVE-2025-35966 | HIGH | 7.5 | 0.6% | Jul 22, 2025 | A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2... |
| CVE-2025-8018 | HIGH | 8.8 | 0.4% | Jul 22, 2025 | A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected b... |
| CVE-2025-8015 | MEDIUM | 6.4 | 0.2% | Jul 22, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an ... |
| CVE-2025-51865 | HIGH | 8.8 | 0.4% | Jul 22, 2025 | Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now