2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46686 | LOW | 3.5 | 0.3% | Jul 23, 2025 | Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated ... |
| CVE-2025-4878 | LOW | 3.6 | 0.2% | Jul 22, 2025 | A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_f... |
| CVE-2025-52580 | LOW | 2.4 | 0.2% | Jul 22, 2025 | Insertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploi... |
| CVE-2025-44657 | LOW | 3.9 | 0.3% | Jul 21, 2025 | In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file... |
| CVE-2025-54352 | LOW | 3.7 | 0.3% | Jul 21, 2025 | WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC... |
| CVE-2025-49087 | LOW | 3.7 | 0.4% | Jul 20, 2025 | In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to... |
| CVE-2025-7882 | LOW | 3.1 | 0.3% | Jul 20, 2025 | A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue... |
| CVE-2025-7881 | LOW | 2.7 | 0.3% | Jul 20, 2025 | A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vu... |
| CVE-2025-54314 | LOW | 2.8 | 0.2% | Jul 20, 2025 | Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier becau... |
| CVE-2025-53901 | LOW | 3.5 | 0.3% | Jul 18, 2025 | Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation ... |
| CVE-2025-7789 | LOW | 3.7 | 0.3% | Jul 18, 2025 | A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the fu... |
| CVE-2025-6227 | LOW | 3.1 | 0.2% | Jul 18, 2025 | Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which al... |
| CVE-2025-7748 | LOW | 3.5 | 0.2% | Jul 17, 2025 | A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the compon... |
| CVE-2025-7339 | LOW | 3.4 | 0.2% | Jul 17, 2025 | on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0... |
| CVE-2025-53904 | LOW | 1.3 | 0.3% | Jul 16, 2025 | The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` con... |
| CVE-2025-53840 | LOW | 2.4 | 0.3% | Jul 16, 2025 | Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2... |
| CVE-2025-7703 | LOW | 3.1 | 0.3% | Jul 16, 2025 | Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage. |
| CVE-2025-52687 | LOW | 2.4 | 0.2% | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point... |
| CVE-2025-53029 | LOW | 2.3 | 0.2% | Jul 15, 2025 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2025-50104 | LOW | 2.7 | 0.4% | Jul 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte... |
| CVE-2025-50100 | LOW | 2.2 | 0.4% | Jul 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that ... |
| CVE-2025-50098 | LOW | 2.7 | 0.4% | Jul 15, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2025-50081 | LOW | 3.1 | 0.2% | Jul 15, 2025 | Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a... |
| CVE-2025-50066 | LOW | 2.7 | 0.3% | Jul 15, 2025 | Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are... |
| CVE-2025-50065 | LOW | 3.7 | 0.3% | Jul 15, 2025 | Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now