2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71394 | MEDIUM | 4.3 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut... |
| CVE-2025-71393 | MEDIUM | 6.5 | 0.2% | Jul 18, 2026 | SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e... |
| CVE-2025-71392 | HIGH | 8 | 0.2% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the... |
| CVE-2025-71391 | MEDIUM | 6.5 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated ... |
| CVE-2025-71390 | HIGH | 8.8 | 0.2% | Jul 18, 2026 | SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames agains... |
| CVE-2025-51678 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to une... |
| CVE-2025-51677 | CRITICAL | 9.1 | 0.4% | Jul 17, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12... |
| CVE-2025-59866 | LOW | 3.3 | — | Jul 17, 2026 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es... |
| CVE-2025-60357 | HIGH | 8.1 | 0.3% | Jul 17, 2026 | AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv... |
| CVE-2025-45870 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet c... |
| CVE-2025-45868 | HIGH | 8.8 | 0.2% | Jul 16, 2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allo... |
| CVE-2025-71388 | HIGH | 7.6 | 0.5% | Jul 16, 2026 | stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission ... |
| CVE-2025-71377 | HIGH | 8.7 | 0.7% | Jul 16, 2026 | stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching me... |
| CVE-2025-65720 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user... |
| CVE-2025-32781 | MEDIUM | 6.5 | 0.4% | Jul 15, 2026 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior... |
| CVE-2025-56365 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model co... |
| CVE-2025-56364 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestin... |
| CVE-2025-56363 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevi... |
| CVE-2025-56362 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Lev... |
| CVE-2025-56361 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev... |
| CVE-2025-62826 | MEDIUM | 4.3 | 0.4% | Jul 14, 2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera... |
| CVE-2025-62675 | MEDIUM | 4.3 | 0.3% | Jul 14, 2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera... |
| CVE-2025-53379 | HIGH | 7.5 | — | Jul 14, 2026 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio... |
| CVE-2025-43892 | MEDIUM | 4.3 | — | Jul 14, 2026 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v... |
| CVE-2025-11698 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerabilit... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now