2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6232 | HIGH | 8.5 | 0.2% | Jul 17, 2025 | An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at... |
| CVE-2025-6231 | HIGH | 8.5 | 0.2% | Jul 17, 2025 | An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at... |
| CVE-2025-4657 | HIGH | 8.4 | 0.2% | Jul 17, 2025 | A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Le... |
| CVE-2025-3753 | HIGH | 7.8 | 0.2% | Jul 17, 2025 | A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS dist... |
| CVE-2025-23270 | HIGH | 7.1 | 0.2% | Jul 17, 2025 | NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exp... |
| CVE-2025-23267 | HIGH | 8.5 | 0.7% | Jul 17, 2025 | NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could ... |
| CVE-2025-1700 | HIGH | 7.1 | 0.1% | Jul 17, 2025 | A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that coul... |
| CVE-2025-0886 | HIGH | 8.5 | 0.2% | Jul 17, 2025 | An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authe... |
| CVE-2025-7472 | HIGH | 7.5 | 0.1% | Jul 17, 2025 | A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a loc... |
| CVE-2025-53817 | HIGH | 7.5 | 0.6% | Jul 17, 2025 | 7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to vers... |
| CVE-2025-53816 | HIGH | 7.5 | 0.6% | Jul 17, 2025 | 7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to m... |
| CVE-2025-7747 | HIGH | 8.8 | 0.8% | Jul 17, 2025 | A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle... |
| CVE-2025-23263 | HIGH | 7.6 | 0.2% | Jul 17, 2025 | NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause es... |
| CVE-2025-7338 | HIGH | 7.5 | 0.6% | Jul 17, 2025 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1... |
| CVE-2025-54062 | HIGH | 8.8 | 0.5% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-54061 | HIGH | 8.8 | 0.5% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-54060 | HIGH | 8.8 | 0.5% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-54058 | HIGH | 8.8 | 0.5% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-53946 | HIGH | 8.8 | 0.4% | Jul 17, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection... |
| CVE-2025-53909 | HIGH | 7.2 | 0.5% | Jul 17, 2025 | mailcow: dockerized is an open source groupware/email suite based on docker. A Server-Side Template Injection (SSTI) vul... |
| CVE-2025-1713 | HIGH | 7.5 | 0.7% | Jul 17, 2025 | When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream brid... |
| CVE-2025-5344 | HIGH | 8.5 | 0.1% | Jul 17, 2025 | Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.blu... |
| CVE-2025-7735 | HIGH | 8.7 | 0.4% | Jul 17, 2025 | The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote a... |
| CVE-2025-34130 | HIGH | 8.7 | 1.1% | Jul 16, 2025 | An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.... |
| CVE-2025-34129 | HIGH | 8.7 | 1.1% | Jul 16, 2025 | A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now