2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0886 | HIGH | 8.5 | 0.2% | Jul 17, 2025 | An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authe... |
| CVE-2025-7750 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Aff... |
| CVE-2025-7472 | HIGH | 7.5 | 0.1% | Jul 17, 2025 | A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a loc... |
| CVE-2025-54070 | MEDIUM | 6.9 | 0.3% | Jul 17, 2025 | OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 5.2.0 and prior to versio... |
| CVE-2025-54068 | CRITICAL | 9.8 | 95.4% | Jul 17, 2025 | Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauth... |
| CVE-2025-53817 | HIGH | 7.5 | 0.6% | Jul 17, 2025 | 7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to vers... |
| CVE-2025-53816 | HIGH | 7.5 | 0.6% | Jul 17, 2025 | 7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to m... |
| CVE-2025-50240 | CRITICAL | 9.8 | 0.3% | Jul 17, 2025 | nbcio-boot v1.0.3 was discovered to contain a SQL injection vulnerability via the userIds parameter at /sys/user/deleteR... |
| CVE-2025-46102 | MEDIUM | 5.4 | 0.3% | Jul 17, 2025 | Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Referenc... |
| CVE-2025-7749 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0... |
| CVE-2025-7748 | LOW | 3.5 | 0.2% | Jul 17, 2025 | A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the compon... |
| CVE-2025-7747 | HIGH | 8.8 | 0.8% | Jul 17, 2025 | A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle... |
| CVE-2025-53644 | CRITICAL | 9.8 | 0.4% | Jul 17, 2025 | OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on s... |
| CVE-2025-53638 | MEDIUM | 6.9 | 0.3% | Jul 17, 2025 | Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, w... |
| CVE-2025-51497 | MEDIUM | 5.5 | 0.1% | Jul 17, 2025 | An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Saf... |
| CVE-2025-23263 | HIGH | 7.6 | 0.2% | Jul 17, 2025 | NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause es... |
| CVE-2025-7339 | LOW | 3.4 | 0.2% | Jul 17, 2025 | on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0... |
| CVE-2025-7338 | HIGH | 7.5 | 0.6% | Jul 17, 2025 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1... |
| CVE-2025-53867 | CRITICAL | 9.8 | 0.7% | Jul 17, 2025 | Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL. |
| CVE-2025-52046 | CRITICAL | 9.8 | 5.2% | Jul 17, 2025 | Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 functio... |
| CVE-2025-25257 | CRITICAL | 9.8 | 96.7% | Jul 17, 2025 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi... |
| CVE-2025-54066 | MEDIUM | 4.7 | 0.3% | Jul 17, 2025 | DiracX-Web is a web application that provides an interface to interact with the DiracX services. Prior to version 0.1.0-... |
| CVE-2025-54064 | MEDIUM | 6.9 | 0.4% | Jul 17, 2025 | Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da... |
| CVE-2025-54062 | HIGH | 8.8 | 0.5% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-54061 | HIGH | 8.8 | 0.5% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now