2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30752 | LOW | 3.7 | 0.6% | Jul 15, 2025 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). The suppo... |
| CVE-2025-30750 | LOW | 2.4 | 0.2% | Jul 15, 2025 | Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-1... |
| CVE-2025-53903 | LOW | 1.3 | 0.3% | Jul 15, 2025 | The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/users.js` doe... |
| CVE-2025-7577 | LOW | 3.7 | 0.3% | Jul 14, 2025 | A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problem... |
| CVE-2025-7569 | LOW | 3.5 | 0.2% | Jul 14, 2025 | A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerab... |
| CVE-2025-7554 | LOW | 2.4 | 0.2% | Jul 14, 2025 | A vulnerability classified as problematic was found in Sapido RB-1802 1.0.32. This vulnerability affects unknown code of... |
| CVE-2025-7453 | LOW | 3.7 | 0.4% | Jul 11, 2025 | A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects t... |
| CVE-2025-51591 | LOW | 3.7 | 0.6% | Jul 11, 2025 | A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole in... |
| CVE-2025-53862 | LOW | 3.5 | 0.2% | Jul 11, 2025 | A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw... |
| CVE-2025-53861 | LOW | 3.1 | 0.1% | Jul 11, 2025 | A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the... |
| CVE-2025-5992 | LOW | 2.3 | 0.3% | Jul 11, 2025 | When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for... |
| CVE-2025-7435 | LOW | 3.5 | 0.2% | Jul 11, 2025 | A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It ... |
| CVE-2025-49462 | LOW | 3.5 | 0.2% | Jul 10, 2025 | Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosu... |
| CVE-2025-27613 | LOW | 3.6 | 0.3% | Jul 10, 2025 | Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs git... |
| CVE-2025-6168 | LOW | 2.7 | 0.3% | Jul 10, 2025 | An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that cou... |
| CVE-2025-4972 | LOW | 2.7 | 0.3% | Jul 10, 2025 | An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that cou... |
| CVE-2025-7215 | LOW | 1.6 | 0.1% | Jul 9, 2025 | A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this... |
| CVE-2025-7214 | LOW | 1.6 | 0.1% | Jul 9, 2025 | A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is... |
| CVE-2025-49546 | LOW | 2.4 | 0.4% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that c... |
| CVE-2025-49760 | LOW | 3.5 | 1.3% | Jul 8, 2025 | External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a networ... |
| CVE-2025-49756 | LOW | 3.3 | 0.2% | Jul 8, 2025 | Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a ... |
| CVE-2025-49731 | LOW | 3.1 | 0.4% | Jul 8, 2025 | Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate ... |
| CVE-2025-0293 | LOW | 2.7 | 0.4% | Jul 8, 2025 | CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows ... |
| CVE-2025-5450 | LOW | 2.7 | 0.2% | Jul 8, 2025 | Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Iva... |
| CVE-2025-24474 | LOW | 2.7 | 0.2% | Jul 8, 2025 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiM... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now