2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53359 | MEDIUM | 6.9 | 0.4% | Jul 2, 2025 | ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EI... |
| CVE-2025-53358 | MEDIUM | 6.5 | 0.4% | Jul 2, 2025 | kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/... |
| CVE-2025-52886 | MEDIUM | 5.9 | 0.4% | Jul 2, 2025 | Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std... |
| CVE-2025-20310 | MEDIUM | 6.1 | 0.2% | Jul 2, 2025 | A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker t... |
| CVE-2025-20308 | MEDIUM | 6.7 | 0.2% | Jul 2, 2025 | A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute... |
| CVE-2025-6725 | MEDIUM | 5.4 | 0.2% | Jul 2, 2025 | In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has a... |
| CVE-2025-53494 | MEDIUM | 6.5 | 0.2% | Jul 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53493 | MEDIUM | 6.5 | 0.2% | Jul 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53492 | LOW | 3.7 | 0.2% | Jul 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53110 | HIGH | 7.3 | 0.5% | Jul 2, 2025 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio... |
| CVE-2025-53109 | HIGH | 7.3 | 0.7% | Jul 2, 2025 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio... |
| CVE-2025-53108 | MEDIUM | 5.3 | 0.3% | Jul 2, 2025 | HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in ... |
| CVE-2025-53006 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreS... |
| CVE-2025-52891 | MEDIUM | 6.5 | 0.3% | Jul 2, 2025 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versio... |
| CVE-2025-38093 | MEDIUM | 5.5 | 0.1% | Jul 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: x1e80100: Add GPU cooling Unlike... |
| CVE-2025-38092 | MEDIUM | 5.5 | 0.1% | Jul 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use list_first_entry_or_null for opinfo_get_... |
| CVE-2025-38091 | HIGH | 7.8 | 0.1% | Jul 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check stream id dml21 wrapper to g... |
| CVE-2025-53106 | HIGH | 8.8 | 0.5% | Jul 2, 2025 | Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-... |
| CVE-2025-49588 | HIGH | 8.7 | 0.3% | Jul 2, 2025 | Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve... |
| CVE-2025-45029 | MEDIUM | 6.5 | 0.2% | Jul 2, 2025 | WINSTAR WN572HP3 v230525 was discovered to contain a heap overflow via the CONTENT_LENGTH variable at /cgi-bin/upload.cg... |
| CVE-2025-34073 | CRITICAL | 10 | 3.9% | Jul 2, 2025 | An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote atta... |
| CVE-2025-34072 | CRITICAL | 9.3 | 0.4% | Jul 2, 2025 | A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automat... |
| CVE-2025-34071 | CRITICAL | 9.8 | 0.7% | Jul 2, 2025 | A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload a... |
| CVE-2025-34070 | CRITICAL | 9.8 | 0.7% | Jul 2, 2025 | A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remot... |
| CVE-2025-34069 | CRITICAL | 9.8 | 0.6% | Jul 2, 2025 | An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now