2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6076 | HIGH | 8.8 | 0.7% | Aug 2, 2025 | Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "repor... |
| CVE-2025-54796 | HIGH | 7.5 | 0.4% | Aug 2, 2025 | Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows... |
| CVE-2025-54782 | HIGH | 8.8 | 46.2% | Aug 2, 2025 | Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remo... |
| CVE-2025-54136 | HIGH | 8.8 | 7.5% | Aug 2, 2025 | Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per... |
| CVE-2025-54132 | HIGH | 7.5 | 0.3% | Aug 1, 2025 | Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams)... |
| CVE-2025-54131 | HIGH | 8.8 | 0.5% | Aug 1, 2025 | Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in a... |
| CVE-2025-8480 | HIGH | 8 | 0.7% | Aug 1, 2025 | Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute ... |
| CVE-2025-8477 | HIGH | 7.4 | 0.3% | Aug 1, 2025 | Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2025-8476 | HIGH | 8 | 0.1% | Aug 1, 2025 | Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers... |
| CVE-2025-8475 | HIGH | 7.4 | 0.3% | Aug 1, 2025 | Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-... |
| CVE-2025-8472 | HIGH | 7.4 | 0.3% | Aug 1, 2025 | Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2025-5999 | HIGH | 7.2 | 0.5% | Aug 1, 2025 | A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or... |
| CVE-2025-54595 | HIGH | 7.3 | 0.2% | Aug 1, 2025 | Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged he... |
| CVE-2025-54593 | HIGH | 7.2 | 0.7% | Aug 1, 2025 | FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can ... |
| CVE-2025-54564 | HIGH | 7.8 | 0.2% | Aug 1, 2025 | uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allow... |
| CVE-2025-53012 | HIGH | 7.5 | 0.8% | Aug 1, 2025 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren... |
| CVE-2025-53011 | HIGH | 7.5 | 0.5% | Aug 1, 2025 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren... |
| CVE-2025-53010 | HIGH | 7.5 | 0.4% | Aug 1, 2025 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren... |
| CVE-2025-53009 | HIGH | 7.5 | 0.6% | Aug 1, 2025 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren... |
| CVE-2025-2824 | HIGH | 7.4 | 0.3% | Aug 1, 2025 | IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to condu... |
| CVE-2025-51504 | HIGH | 7.6 | 0.5% | Aug 1, 2025 | Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last n... |
| CVE-2025-52361 | HIGH | 7.8 | 0.2% | Aug 1, 2025 | Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allo... |
| CVE-2025-52327 | HIGH | 7.8 | 0.2% | Aug 1, 2025 | SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via t... |
| CVE-2025-44139 | HIGH | 7.2 | 0.7% | Aug 1, 2025 | Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upl... |
| CVE-2025-45767 | HIGH | 7 | 0.1% | Aug 1, 2025 | jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now