2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53535 | LOW | 2.1 | 0.3% | Jul 7, 2025 | Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the origin... |
| CVE-2025-3777 | LOW | 3.5 | 0.3% | Jul 7, 2025 | Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image... |
| CVE-2025-53177 | LOW | 3.9 | 0.1% | Jul 7, 2025 | Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may... |
| CVE-2025-53176 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-53175 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-53174 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-53172 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-53171 | LOW | 3.3 | 0.1% | Jul 7, 2025 | Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-7080 | LOW | 3.7 | 0.4% | Jul 6, 2025 | A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080... |
| CVE-2025-7061 | LOW | 2.7 | 0.3% | Jul 4, 2025 | A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerabilit... |
| CVE-2025-49005 | LOW | 3.7 | 0.4% | Jul 3, 2025 | Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.... |
| CVE-2025-0885 | LOW | 1.8 | 0.1% | Jul 3, 2025 | Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2025-6942 | LOW | 3.8 | 0.1% | Jul 2, 2025 | The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited duri... |
| CVE-2025-53492 | LOW | 3.7 | 0.2% | Jul 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-24335 | LOW | 2 | 0.4% | Jul 2, 2025 | Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, wh... |
| CVE-2025-24334 | LOW | 3.3 | 0.1% | Jul 2, 2025 | The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release vers... |
| CVE-2025-52463 | LOW | 3.1 | 0.1% | Jul 2, 2025 | Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and earlier. If this vulnerab... |
| CVE-2025-4654 | LOW | 3.7 | 0.2% | Jul 2, 2025 | The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper au... |
| CVE-2025-6932 | LOW | 3.7 | 0.9% | Jun 30, 2025 | A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the functi... |
| CVE-2025-40710 | LOW | 2.3 | 0.3% | Jun 30, 2025 | Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when a... |
| CVE-2025-6817 | LOW | 3.3 | 0.2% | Jun 28, 2025 | A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C... |
| CVE-2025-6816 | LOW | 3.3 | 0.2% | Jun 28, 2025 | A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_... |
| CVE-2025-52992 | LOW | 3.2 | 0.1% | Jun 27, 2025 | The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow a... |
| CVE-2025-52991 | LOW | 3.2 | 0.1% | Jun 27, 2025 | The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writa... |
| CVE-2025-46416 | LOW | 2.9 | 0.2% | Jun 27, 2025 | The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now