2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21000 | LOW | 3.3 | 0.1% | Jul 8, 2025 | Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth. |
| CVE-2025-20999 | LOW | 2.1 | 0.1% | Jul 8, 2025 | Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows second... |
| CVE-2025-20998 | LOW | 3.3 | 0.1% | Jul 8, 2025 | Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to acc... |
| CVE-2025-42978 | LOW | 3.5 | 0.1% | Jul 8, 2025 | The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not re... |
| CVE-2025-42954 | LOW | 2.7 | 0.4% | Jul 8, 2025 | SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a R... |
| CVE-2025-53535 | LOW | 2.1 | 0.3% | Jul 7, 2025 | Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the origin... |
| CVE-2025-3777 | LOW | 3.5 | 0.3% | Jul 7, 2025 | Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image... |
| CVE-2025-53177 | LOW | 3.9 | 0.1% | Jul 7, 2025 | Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may... |
| CVE-2025-53176 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-53175 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-53174 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-53172 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-53171 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-7080 | LOW | 3.7 | 0.4% | Jul 6, 2025 | A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080... |
| CVE-2025-7061 | LOW | 2.7 | 0.3% | Jul 4, 2025 | A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerabilit... |
| CVE-2025-49005 | LOW | 3.7 | 0.4% | Jul 3, 2025 | Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.... |
| CVE-2025-0885 | LOW | 1.8 | 0.1% | Jul 3, 2025 | Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2025-6942 | LOW | 3.8 | 0.1% | Jul 2, 2025 | The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited duri... |
| CVE-2025-53492 | LOW | 3.7 | 0.2% | Jul 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-24335 | LOW | 2 | 0.4% | Jul 2, 2025 | Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, wh... |
| CVE-2025-24334 | LOW | 3.3 | 0.1% | Jul 2, 2025 | The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release vers... |
| CVE-2025-52463 | LOW | 3.1 | 0.1% | Jul 2, 2025 | Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and earlier. If this vulnerab... |
| CVE-2025-4654 | LOW | 3.7 | 0.2% | Jul 2, 2025 | The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper au... |
| CVE-2025-6932 | LOW | 3.7 | 0.9% | Jun 30, 2025 | A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the functi... |
| CVE-2025-40710 | LOW | 2.3 | 0.3% | Jun 30, 2025 | Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now