2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49464 | MEDIUM | 6.5 | 0.6% | Jul 10, 2025 | Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service ... |
| CVE-2025-49463 | MEDIUM | 6.5 | 0.4% | Jul 10, 2025 | Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated u... |
| CVE-2025-49462 | LOW | 3.5 | 0.2% | Jul 10, 2025 | Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosu... |
| CVE-2025-47813 | MEDIUM | 4.3 | 56.4% | Jul 10, 2025 | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a ... |
| CVE-2025-47812 | CRITICAL | 10 | 95.3% | Jul 10, 2025 | In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o... |
| CVE-2025-47811 | MEDIUM | 6.6 | 3.5% | Jul 10, 2025 | In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or S... |
| CVE-2025-27889 | HIGH | 8.8 | 0.4% | Jul 10, 2025 | Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint... |
| CVE-2025-23048 | CRITICAL | 9.1 | 1.0% | Jul 10, 2025 | In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clien... |
| CVE-2025-6395 | MEDIUM | 6.5 | 0.7% | Jul 10, 2025 | A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite(). |
| CVE-2025-53364 | MEDIUM | 5.3 | 0.8% | Jul 10, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.... |
| CVE-2025-46789 | MEDIUM | 6.5 | 0.4% | Jul 10, 2025 | Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service ... |
| CVE-2025-46788 | CRITICAL | 9.1 | 0.2% | Jul 10, 2025 | Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to cond... |
| CVE-2025-7408 | MEDIUM | 5.4 | 0.2% | Jul 10, 2025 | A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerabi... |
| CVE-2025-7370 | — | — | — | Jul 10, 2025 | Rejected reason: Upon investigtion upstream maintainers discovered this was not a real issue. See the references for mor... |
| CVE-2025-7365 | HIGH | 7.1 | 0.2% | Jul 10, 2025 | A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account du... |
| CVE-2025-46835 | HIGH | 8.5 | 0.3% | Jul 10, 2025 | Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository ... |
| CVE-2025-46334 | HIGH | 8.6 | 0.3% | Jul 10, 2025 | Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of... |
| CVE-2025-44251 | HIGH | 7.5 | 0.2% | Jul 10, 2025 | Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process. |
| CVE-2025-36090 | MEDIUM | 5.3 | 0.3% | Jul 10, 2025 | IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the applicati... |
| CVE-2025-27614 | HIGH | 8.6 | 0.3% | Jul 10, 2025 | Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that wit... |
| CVE-2025-27613 | LOW | 3.6 | 0.3% | Jul 10, 2025 | Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs git... |
| CVE-2025-7425 | HIGH | 7.8 | 0.3% | Jul 10, 2025 | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory m... |
| CVE-2025-7424 | HIGH | 7.5 | 1.2% | Jul 10, 2025 | A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which ... |
| CVE-2025-7407 | HIGH | 8.8 | 8.3% | Jul 10, 2025 | A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of... |
| CVE-2025-6211 | MEDIUM | 6.5 | 0.3% | Jul 10, 2025 | A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now