2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6971 | HIGH | 7.8 | 0.2% | Jul 15, 2025 | Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWOR... |
| CVE-2025-53622 | MEDIUM | 5.2 | 0.4% | Jul 15, 2025 | DSpace open source software is a repository application which provides durable access to digital resources. Prior to ver... |
| CVE-2025-53621 | MEDIUM | 6.9 | 0.4% | Jul 15, 2025 | DSpace open source software is a repository application which provides durable access to digital resources. Two related ... |
| CVE-2025-52379 | MEDIUM | 5.4 | 9.7% | Jul 15, 2025 | Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerabili... |
| CVE-2025-52378 | MEDIUM | 5.4 | 5.9% | Jul 15, 2025 | Cross-Site Scripting (XSS) vulnerability in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below allowing at... |
| CVE-2025-52377 | MEDIUM | 5.4 | 9.0% | Jul 15, 2025 | Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authentica... |
| CVE-2025-48795 | MEDIUM | 5.6 | 0.6% | Jul 15, 2025 | Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which mea... |
| CVE-2025-33097 | MEDIUM | 5.4 | 0.2% | Jul 15, 2025 | IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authentica... |
| CVE-2025-30483 | MEDIUM | 5.5 | 0.1% | Jul 15, 2025 | Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log ... |
| CVE-2025-0831 | HIGH | 7.8 | 0.2% | Jul 15, 2025 | Out-Of-Bounds Read vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS D... |
| CVE-2025-6965 | HIGH | 7.7 | 73.5% | Jul 15, 2025 | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the numbe... |
| CVE-2025-52376 | CRITICAL | 9.8 | 9.1% | Jul 15, 2025 | An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router ... |
| CVE-2025-34116 | HIGH | 8.7 | 1.1% | Jul 15, 2025 | A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI in... |
| CVE-2025-34115 | HIGH | 8.7 | 3.3% | Jul 15, 2025 | An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter... |
| CVE-2025-34113 | HIGH | 8.7 | 2.1% | Jul 15, 2025 | An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14... |
| CVE-2025-34112 | CRITICAL | 10 | 2.0% | Jul 15, 2025 | An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpr... |
| CVE-2025-34111 | CRITICAL | 9.8 | 1.5% | Jul 15, 2025 | An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via th... |
| CVE-2025-34110 | CRITICAL | 9.3 | 1.3% | Jul 15, 2025 | A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att... |
| CVE-2025-34109 | HIGH | 8.5 | 0.3% | Jul 15, 2025 | PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writ... |
| CVE-2025-34108 | HIGH | 8.6 | 0.9% | Jul 15, 2025 | A stack-based buffer overflow vulnerability exists in the login functionality of Disk Pulse Enterprise version 9.0.34. A... |
| CVE-2025-34107 | HIGH | 8.7 | 0.8% | Jul 15, 2025 | A buffer overflow vulnerability exists in the WinaXe FTP Client version 7.7 within the FTP banner parsing functionality,... |
| CVE-2025-34106 | HIGH | 8.4 | 0.3% | Jul 15, 2025 | A buffer overflow vulnerability exists in PDF Shaper versions 3.5 and 3.6 when converting a crafted PDF file to an image... |
| CVE-2025-34105 | CRITICAL | 10 | 1.0% | Jul 15, 2025 | A stack-based buffer overflow vulnerability exists in the built-in web interface of DiskBoss Enterprise versions 7.4.28,... |
| CVE-2025-34104 | CRITICAL | 9.4 | 0.9% | Jul 15, 2025 | An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin... |
| CVE-2025-34103 | CRITICAL | 9.3 | 4.2% | Jul 15, 2025 | An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now