2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71388 | HIGH | 7.6 | 0.3% | Jul 16, 2026 | stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission ... |
| CVE-2025-71377 | HIGH | 8.7 | 0.4% | Jul 16, 2026 | stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching me... |
| CVE-2025-56365 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model co... |
| CVE-2025-56364 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestin... |
| CVE-2025-56363 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevi... |
| CVE-2025-56362 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Lev... |
| CVE-2025-56361 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev... |
| CVE-2025-53379 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio... |
| CVE-2025-40945 | HIGH | 8.5 | 0.1% | Jul 14, 2026 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1),... |
| CVE-2025-45869 | HIGH | 7.3 | — | Jul 13, 2026 | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenti... |
| CVE-2025-6784 | HIGH | 8.8 | 0.5% | Jul 11, 2026 | The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 ... |
| CVE-2025-30007 | HIGH | 8.8 | 2.1% | Jul 10, 2026 | HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticat... |
| CVE-2025-70796 | HIGH | 7.5 | — | Jul 10, 2026 | An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.... |
| CVE-2025-45422 | HIGH | 8.1 | 0.2% | Jul 9, 2026 | Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and mak... |
| CVE-2025-63579 | HIGH | 7.5 | 0.2% | Jul 9, 2026 | Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu... |
| CVE-2025-3110 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote at... |
| CVE-2025-59617 | HIGH | 7.3 | 0.1% | Jul 6, 2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. |
| CVE-2025-59616 | HIGH | 7.8 | 0.1% | Jul 6, 2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea... |
| CVE-2025-59615 | HIGH | 7.8 | 0.1% | Jul 6, 2026 | Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe... |
| CVE-2025-53831 | HIGH | 8.2 | — | Jul 6, 2026 | DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application o... |
| CVE-2025-53829 | HIGH | 8 | 0.3% | Jul 6, 2026 | ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack... |
| CVE-2025-53828 | HIGH | 8.5 | 0.2% | Jul 6, 2026 | SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli... |
| CVE-2025-13475 | HIGH | 7.3 | 0.1% | Jul 4, 2026 | In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes be... |
| CVE-2025-71380 | HIGH | 8.8 | 0.4% | Jul 4, 2026 | The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n ru... |
| CVE-2025-71375 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for mal... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now