2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23288 | LOW | 3.3 | 0.1% | Aug 2, 2025 | NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may cause an exposure of sensitive sys... |
| CVE-2025-23287 | LOW | 3.3 | 0.1% | Aug 2, 2025 | NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access sensitive system-level infor... |
| CVE-2025-54781 | LOW | 2.8 | 0.1% | Aug 2, 2025 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelbla... |
| CVE-2025-6011 | LOW | 3.7 | 0.3% | Aug 1, 2025 | A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish ... |
| CVE-2025-37109 | LOW | 3.5 | 0.2% | Jul 31, 2025 | Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product |
| CVE-2025-37108 | LOW | 3.5 | 0.2% | Jul 31, 2025 | Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product |
| CVE-2025-51385 | LOW | 3.5 | 0.4% | Jul 31, 2025 | D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter. |
| CVE-2025-51384 | LOW | 3.5 | 0.3% | Jul 31, 2025 | D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter. |
| CVE-2025-51383 | LOW | 3.5 | 0.3% | Jul 31, 2025 | D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter. |
| CVE-2025-54085 | LOW | 3.8 | 0.2% | Jul 31, 2025 | CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers ... |
| CVE-2025-49082 | LOW | 2.7 | 0.2% | Jul 31, 2025 | CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers ... |
| CVE-2025-53113 | LOW | 2.7 | 0.2% | Jul 30, 2025 | GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that... |
| CVE-2025-8283 | LOW | 3.7 | 0.3% | Jul 28, 2025 | A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman se... |
| CVE-2025-8225 | LOW | 3.3 | 0.2% | Jul 27, 2025 | A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_de... |
| CVE-2025-8205 | LOW | 3.7 | 0.4% | Jul 26, 2025 | A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by ... |
| CVE-2025-8204 | LOW | 3.7 | 0.6% | Jul 26, 2025 | A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerabilit... |
| CVE-2025-43712 | LOW | 2.9 | 0.2% | Jul 25, 2025 | JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipst... |
| CVE-2025-54568 | LOW | 3.7 | 0.3% | Jul 25, 2025 | Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate... |
| CVE-2025-0253 | LOW | 2.4 | 0.2% | Jul 25, 2025 | HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configu... |
| CVE-2025-7001 | LOW | 2.7 | 0.4% | Jul 24, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.... |
| CVE-2025-46686 | LOW | 3.5 | 0.3% | Jul 23, 2025 | Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated ... |
| CVE-2025-4878 | LOW | 3.6 | 0.2% | Jul 22, 2025 | A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_f... |
| CVE-2025-52580 | LOW | 2.4 | 0.2% | Jul 22, 2025 | Insertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploi... |
| CVE-2025-44657 | LOW | 3.9 | 0.3% | Jul 21, 2025 | In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file... |
| CVE-2025-54352 | LOW | 3.7 | 0.3% | Jul 21, 2025 | WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now