2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38097 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: espintcp: remove encap socket caching to avoid refe... |
| CVE-2025-38096 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: don't warn when if there is a FW err... |
| CVE-2025-38095 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_... |
| CVE-2025-38094 | MEDIUM | 5.5 | 0.1% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: cadence: macb: Fix a possible deadlock in macb... |
| CVE-2025-5944 | MEDIUM | 5.4 | 0.3% | Jul 3, 2025 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-ca... |
| CVE-2025-52842 | MEDIUM | 6.1 | 0.2% | Jul 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Laundry on ... |
| CVE-2025-52559 | MEDIUM | 5.4 | 0.2% | Jul 2, 2025 | Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL ... |
| CVE-2025-43025 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | HP Universal Print Driver is potentially vulnerable to denial of service due to buffer overflow in versions of UPD 7.4 o... |
| CVE-2025-34092 | — | — | — | Jul 2, 2025 | Rejected reason: Neither filed by Chrome nor a valid security vulnerability. |
| CVE-2025-34091 | — | — | — | Jul 2, 2025 | Rejected reason: Neither filed by Chrome nor a valid security vulnerability. |
| CVE-2025-34090 | — | — | — | Jul 2, 2025 | Rejected reason: Neither filed by Chrome nor a valid security vulnerability. |
| CVE-2025-34079 | HIGH | 7.8 | 1.3% | Jul 2, 2025 | An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and Ex... |
| CVE-2025-34078 | HIGH | 7.8 | 0.5% | Jul 2, 2025 | A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web interface and ExternalScripts... |
| CVE-2025-34076 | HIGH | 7.2 | 1.3% | Jul 2, 2025 | An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the ba... |
| CVE-2025-34075 | — | — | — | Jul 2, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Initially assigned to docum... |
| CVE-2025-34074 | CRITICAL | 9.4 | 1.1% | Jul 2, 2025 | An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design i... |
| CVE-2025-49713 | HIGH | 8.8 | 0.7% | Jul 2, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2025-45813 | CRITICAL | 9.8 | 0.4% | Jul 2, 2025 | ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials. |
| CVE-2025-52841 | HIGH | 8.8 | 0.2% | Jul 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This i... |
| CVE-2025-45814 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v... |
| CVE-2025-45424 | MEDIUM | 5.3 | 0.3% | Jul 2, 2025 | Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication. |
| CVE-2025-20309 | CRITICAL | 10 | 1.1% | Jul 2, 2025 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma... |
| CVE-2025-20307 | MEDIUM | 4.8 | 0.2% | Jul 2, 2025 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an ... |
| CVE-2025-6943 | MEDIUM | 4 | 0.1% | Jul 2, 2025 | Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator... |
| CVE-2025-6942 | LOW | 3.8 | 0.1% | Jul 2, 2025 | The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited duri... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now