2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6390 | MEDIUM | 4.4 | 0.1% | Jul 10, 2025 | Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installati... |
| CVE-2025-4662 | MEDIUM | 4.4 | 0.1% | Jul 10, 2025 | Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while execut... |
| CVE-2025-3947 | HIGH | 8.2 | 0.3% | Jul 10, 2025 | The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). A... |
| CVE-2025-3946 | HIGH | 8.2 | 0.5% | Jul 10, 2025 | The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the comp... |
| CVE-2025-2523 | CRITICAL | 9.4 | 0.7% | Jul 10, 2025 | The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Con... |
| CVE-2025-2522 | MEDIUM | 6.5 | 0.2% | Jul 10, 2025 | The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the compon... |
| CVE-2025-2521 | HIGH | 8.6 | 0.4% | Jul 10, 2025 | The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Acce... |
| CVE-2025-7413 | HIGH | 8.8 | 0.3% | Jul 10, 2025 | A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part ... |
| CVE-2025-7412 | HIGH | 8.8 | 0.3% | Jul 10, 2025 | A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is ... |
| CVE-2025-7021 | MEDIUM | 6.5 | 0.3% | Jul 10, 2025 | Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on ... |
| CVE-2025-53634 | HIGH | 7.5 | 0.4% | Jul 10, 2025 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes h... |
| CVE-2025-53633 | CRITICAL | 9.8 | 0.5% | Jul 10, 2025 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.... |
| CVE-2025-53632 | CRITICAL | 9.1 | 0.7% | Jul 10, 2025 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.... |
| CVE-2025-53630 | HIGH | 8.9 | 0.3% | Jul 10, 2025 | llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in g... |
| CVE-2025-53629 | HIGH | 7.5 | 0.5% | Jul 10, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests usi... |
| CVE-2025-53628 | HIGH | 8.8 | 0.4% | Jul 10, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not ... |
| CVE-2025-53506 | HIGH | 7.5 | 1.9% | Jul 10, 2025 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial set... |
| CVE-2025-45662 | MEDIUM | 6.1 | 0.2% | Jul 10, 2025 | A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attack... |
| CVE-2025-34102 | CRITICAL | 9.3 | 6.8% | Jul 10, 2025 | A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploi... |
| CVE-2025-34101 | CRITICAL | 9.3 | 3.1% | Jul 10, 2025 | An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, i... |
| CVE-2025-34100 | CRITICAL | 9.3 | 2.3% | Jul 10, 2025 | An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file man... |
| CVE-2025-34099 | CRITICAL | 9.3 | 1.2% | Jul 10, 2025 | An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vici... |
| CVE-2025-34098 | HIGH | 7.1 | 0.7% | Jul 10, 2025 | A path traversal vulnerability exists in Riverbed SteelHead VCX appliances (confirmed in VCX255U 9.6.0a) due to improper... |
| CVE-2025-34097 | HIGH | 8.6 | 1.0% | Jul 10, 2025 | An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of upl... |
| CVE-2025-34096 | CRITICAL | 9.3 | 1.1% | Jul 10, 2025 | A stack-based buffer overflow vulnerability exists in Easy File Sharing HTTP Server version 7.2. The flaw is triggered w... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now