2025 CVE Vulnerabilities
45,262 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6386 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within t... |
| CVE-2025-6210 | MEDIUM | 6.2 | 0.3% | Jul 7, 2025 | A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, al... |
| CVE-2025-5472 | MEDIUM | 6.5 | 0.3% | Jul 7, 2025 | The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive... |
| CVE-2025-4779 | MEDIUM | 6.1 | 0.4% | Jul 7, 2025 | lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attack... |
| CVE-2025-3777 | LOW | 3.5 | 0.3% | Jul 7, 2025 | Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image... |
| CVE-2025-3705 | MEDIUM | 6.8 | 0.8% | Jul 7, 2025 | A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of sp... |
| CVE-2025-3626 | CRITICAL | 9.1 | 0.9% | Jul 7, 2025 | A remote attacker with administrator account can gain full control of the device due to improper neutralization of speci... |
| CVE-2025-3467 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vu... |
| CVE-2025-3466 | HIGH | 7.2 | 0.7% | Jul 7, 2025 | langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbi... |
| CVE-2025-3264 | MEDIUM | 5.3 | 0.4% | Jul 7, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp... |
| CVE-2025-3263 | MEDIUM | 5.3 | 0.4% | Jul 7, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp... |
| CVE-2025-3262 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, ... |
| CVE-2025-3225 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-... |
| CVE-2025-3046 | HIGH | 7.5 | 0.6% | Jul 7, 2025 | A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allo... |
| CVE-2025-3044 | MEDIUM | 5.3 | 0.3% | Jul 7, 2025 | A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows ... |
| CVE-2025-7121 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects... |
| CVE-2025-7120 | CRITICAL | 9.8 | 0.5% | Jul 7, 2025 | A vulnerability was found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this issu... |
| CVE-2025-3920 | HIGH | 8.5 | 0.1% | Jul 7, 2025 | A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These... |
| CVE-2025-7119 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this... |
| CVE-2025-7118 | HIGH | 8.8 | 0.8% | Jul 7, 2025 | A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affec... |
| CVE-2025-7117 | HIGH | 8.8 | 0.8% | Jul 7, 2025 | A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknow... |
| CVE-2025-7116 | HIGH | 7.5 | 0.8% | Jul 7, 2025 | A vulnerability classified as critical has been found in UTT 进取 750W up to 3.2.2-191225. This affects an unknown part of... |
| CVE-2025-41672 | CRITICAL | 10 | 0.3% | Jul 7, 2025 | A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool a... |
| CVE-2025-7115 | HIGH | 7.3 | 0.4% | Jul 7, 2025 | A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as cr... |
| CVE-2025-7114 | HIGH | 7.5 | 0.5% | Jul 7, 2025 | A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as cri... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now