2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51087 | HIGH | 8.6 | 8.4% | Jul 24, 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of... |
| CVE-2025-33109 | HIGH | 8.8 | 0.4% | Jul 24, 2025 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check.... |
| CVE-2025-7695 | HIGH | 8.8 | 0.6% | Jul 24, 2025 | The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks... |
| CVE-2025-7640 | HIGH | 8.1 | 0.9% | Jul 24, 2025 | The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-26397 | HIGH | 7.8 | 0.3% | Jul 24, 2025 | SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vuln... |
| CVE-2025-54365 | HIGH | 7.5 | 0.7% | Jul 23, 2025 | fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetratio... |
| CVE-2025-54377 | HIGH | 7.8 | 1.1% | Jul 23, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.23.18 and below, RooCode d... |
| CVE-2025-53942 | HIGH | 7.4 | 0.5% | Jul 23, 2025 | authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set o... |
| CVE-2025-53537 | HIGH | 7.5 | 0.4% | Jul 23, 2025 | LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, t... |
| CVE-2025-47281 | HIGH | 7.7 | 0.5% | Jul 23, 2025 | Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial ... |
| CVE-2025-47187 | HIGH | 7.5 | 0.9% | Jul 23, 2025 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th... |
| CVE-2025-8069 | HIGH | 7.8 | 0.2% | Jul 23, 2025 | During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\window... |
| CVE-2025-2634 | HIGH | 7.8 | 0.2% | Jul 23, 2025 | Out of bounds read vulnerability due to improper bounds checking in NI LabVIEW in fontmgr may result in information disc... |
| CVE-2025-2633 | HIGH | 7.8 | 0.2% | Jul 23, 2025 | Out of bounds read vulnerability due to improper bounds checking in NI LabVIEW in lvre!UDecStrToNum that may result in i... |
| CVE-2025-6018 | HIGH | 7.8 | 1.0% | Jul 23, 2025 | A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication... |
| CVE-2025-40597 | HIGH | 7.5 | 27.6% | Jul 23, 2025 | A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to... |
| CVE-2025-40596 | HIGH | 7.3 | 56.1% | Jul 23, 2025 | A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker t... |
| CVE-2025-33077 | HIGH | 8.8 | 0.4% | Jul 23, 2025 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused b... |
| CVE-2025-33076 | HIGH | 8.8 | 0.4% | Jul 23, 2025 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused b... |
| CVE-2025-33020 | HIGH | 7.5 | 0.1% | Jul 23, 2025 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that ... |
| CVE-2025-46099 | HIGH | 7.2 | 0.5% | Jul 23, 2025 | In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module direc... |
| CVE-2025-54297 | HIGH | 7 | 0.2% | Jul 23, 2025 | A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered. |
| CVE-2025-54296 | HIGH | 7 | 0.2% | Jul 23, 2025 | A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered. |
| CVE-2025-50127 | HIGH | 8.5 | 0.3% | Jul 23, 2025 | A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execu... |
| CVE-2025-41684 | HIGH | 8.8 | 0.7% | Jul 23, 2025 | An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now