2025 CVE Vulnerabilities
45,262 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7070 | HIGH | 8.8 | 0.8% | Jul 4, 2025 | A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulner... |
| CVE-2025-53366 | HIGH | 8.7 | 5.7% | Jul 4, 2025 | The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi... |
| CVE-2025-53365 | HIGH | 8.7 | 0.4% | Jul 4, 2025 | The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi... |
| CVE-2025-7069 | MEDIUM | 5.5 | 0.2% | Jul 4, 2025 | A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link... |
| CVE-2025-7068 | MEDIUM | 5.5 | 0.2% | Jul 4, 2025 | A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5F... |
| CVE-2025-53602 | MEDIUM | 5.3 | 0.3% | Jul 4, 2025 | Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-... |
| CVE-2025-7067 | MEDIUM | 5.5 | 0.2% | Jul 4, 2025 | A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_... |
| CVE-2025-53485 | HIGH | 7.5 | 0.3% | Jul 4, 2025 | SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user... |
| CVE-2025-53484 | CRITICAL | 9.8 | 0.5% | Jul 4, 2025 | User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPag... |
| CVE-2025-53483 | HIGH | 8.8 | 0.2% | Jul 4, 2025 | ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF toke... |
| CVE-2025-53482 | MEDIUM | 6.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53481 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Al... |
| CVE-2025-52497 | MEDIUM | 4.8 | 0.3% | Jul 4, 2025 | Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls... |
| CVE-2025-52496 | HIGH | 7.8 | 0.2% | Jul 4, 2025 | Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may b... |
| CVE-2025-49601 | MEDIUM | 6.5 | 0.3% | Jul 4, 2025 | In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes be... |
| CVE-2025-49600 | MEDIUM | 4.9 | 0.1% | Jul 4, 2025 | In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal e... |
| CVE-2025-46733 | HIGH | 7.9 | 0.1% | Jul 4, 2025 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2025-38234 | MEDIUM | 4.7 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======... |
| CVE-2025-38233 | HIGH | 7.8 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix clobbered r15 during livepatc... |
| CVE-2025-38232 | MEDIUM | 4.7 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and export... |
| CVE-2025-38231 | MEDIUM | 5.5 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: nfsd: Initialize ssc before laundromat_work to prev... |
| CVE-2025-38230 | HIGH | 7.8 | 0.2% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: jfs: validate AG parameters in dbMount() to prevent... |
| CVE-2025-38229 | MEDIUM | 5.5 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: cxusb: no longer judge rbuf when the write f... |
| CVE-2025-38228 | MEDIUM | 5.5 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: imagination: fix a potential memory leak in ... |
| CVE-2025-38227 | HIGH | 7.8 | 0.2% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now