2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34095 | CRITICAL | 9.3 | 4.4% | Jul 10, 2025 | An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial inter... |
| CVE-2025-34093 | HIGH | 7.5 | 2.0% | Jul 10, 2025 | An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible ove... |
| CVE-2025-2520 | HIGH | 7.5 | 0.4% | Jul 10, 2025 | The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications.... |
| CVE-2025-7411 | CRITICAL | 9.8 | 0.4% | Jul 10, 2025 | A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulne... |
| CVE-2025-53709 | MEDIUM | 5.4 | 0.2% | Jul 10, 2025 | Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The ... |
| CVE-2025-53626 | MEDIUM | 6.1 | 0.3% | Jul 10, 2025 | pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 ... |
| CVE-2025-53625 | HIGH | 8.7 | 0.4% | Jul 10, 2025 | The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with variou... |
| CVE-2025-53549 | MEDIUM | 5.2 | 0.3% | Jul 10, 2025 | The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection v... |
| CVE-2025-53542 | HIGH | 7.7 | 0.7% | Jul 10, 2025 | Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script ... |
| CVE-2025-53503 | HIGH | 7.8 | 0.2% | Jul 10, 2025 | Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to u... |
| CVE-2025-53378 | CRITICAL | 9.8 | 0.6% | Jul 10, 2025 | A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have all... |
| CVE-2025-52837 | HIGH | 7.8 | 0.2% | Jul 10, 2025 | Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalat... |
| CVE-2025-52521 | HIGH | 7.1 | 0.3% | Jul 10, 2025 | Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou... |
| CVE-2025-52520 | HIGH | 7.5 | 2.0% | Jul 10, 2025 | For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a... |
| CVE-2025-52473 | MEDIUM | 5.5 | 0.2% | Jul 10, 2025 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Mult... |
| CVE-2025-52434 | HIGH | 7.5 | 1.8% | Jul 10, 2025 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc... |
| CVE-2025-28245 | MEDIUM | 6.1 | 0.3% | Jul 10, 2025 | Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web ... |
| CVE-2025-28244 | HIGH | 8.8 | 0.5% | Jul 10, 2025 | Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain... |
| CVE-2025-28243 | HIGH | 8 | 0.3% | Jul 10, 2025 | An issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component. |
| CVE-2025-53371 | CRITICAL | 9.1 | 0.3% | Jul 10, 2025 | DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel... |
| CVE-2025-7410 | CRITICAL | 9.8 | 0.4% | Jul 10, 2025 | A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unkno... |
| CVE-2025-7409 | CRITICAL | 9.8 | 0.4% | Jul 10, 2025 | A vulnerability was found in code-projects Mobile Shop 1.0 and classified as critical. This issue affects some unknown p... |
| CVE-2025-53020 | HIGH | 7.5 | 4.4% | Jul 10, 2025 | Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Ser... |
| CVE-2025-49812 | HIGH | 7.4 | 0.5% | Jul 10, 2025 | In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows... |
| CVE-2025-49630 | HIGH | 7.5 | 1.1% | Jul 10, 2025 | In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now