2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49746 | HIGH | 8.8 | 0.7% | Jul 18, 2025 | Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-47995 | HIGH | 8.8 | 0.6% | Jul 18, 2025 | Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-47158 | CRITICAL | 9 | 0.7% | Jul 18, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov... |
| CVE-2025-45157 | MEDIUM | 6.5 | 0.2% | Jul 18, 2025 | Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users. |
| CVE-2025-45156 | MEDIUM | 5.3 | 0.4% | Jul 18, 2025 | Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users. |
| CVE-2025-7791 | MEDIUM | 5.4 | 0.2% | Jul 18, 2025 | A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declared as problematic. T... |
| CVE-2025-7790 | MEDIUM | 6.5 | 0.8% | Jul 18, 2025 | A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part... |
| CVE-2025-7789 | LOW | 3.7 | 0.3% | Jul 18, 2025 | A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the fu... |
| CVE-2025-54079 | HIGH | 8.8 | 0.4% | Jul 18, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-54078 | MEDIUM | 6.1 | 0.2% | Jul 18, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-54077 | MEDIUM | 6.1 | 0.2% | Jul 18, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-54076 | MEDIUM | 6.1 | 0.2% | Jul 18, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-54075 | HIGH | 8.3 | 0.3% | Jul 18, 2025 | MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.1... |
| CVE-2025-54073 | HIGH | 7.5 | 8.1% | Jul 18, 2025 | mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documenta... |
| CVE-2025-54059 | MEDIUM | 4.4 | 0.1% | Jul 18, 2025 | melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version ... |
| CVE-2025-53945 | HIGH | 7 | 0.1% | Jul 18, 2025 | apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prio... |
| CVE-2025-53888 | CRITICAL | 9.8 | 0.7% | Jul 18, 2025 | RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `a... |
| CVE-2025-7788 | HIGH | 8.8 | 5.4% | Jul 18, 2025 | A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability... |
| CVE-2025-7787 | HIGH | 8.8 | 0.4% | Jul 18, 2025 | A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function ht... |
| CVE-2025-46732 | MEDIUM | 5.4 | 0.2% | Jul 18, 2025 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2025-46000 | MEDIUM | 6.5 | 0.4% | Jul 18, 2025 | An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2... |
| CVE-2025-7786 | MEDIUM | 5.4 | 0.2% | Jul 18, 2025 | A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects som... |
| CVE-2025-7784 | MEDIUM | 6.5 | 0.4% | Jul 18, 2025 | A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are e... |
| CVE-2025-46002 | MEDIUM | 6.5 | 1.6% | Jul 18, 2025 | An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP re... |
| CVE-2025-46001 | CRITICAL | 9.8 | 0.6% | Jul 18, 2025 | An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now