2025 CVE Vulnerabilities
45,345 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46358 | HIGH | 8.5 | 0.2% | Jul 11, 2025 | Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense agai... |
| CVE-2025-7419 | HIGH | 8.8 | 0.8% | Jul 10, 2025 | A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fr... |
| CVE-2025-7418 | HIGH | 8.8 | 0.8% | Jul 10, 2025 | A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the functio... |
| CVE-2025-1727 | HIGH | 8.1 | 0.5% | Jul 10, 2025 | The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH ... |
| CVE-2025-7417 | HIGH | 8.8 | 0.8% | Jul 10, 2025 | A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability i... |
| CVE-2025-7416 | HIGH | 8.8 | 0.8% | Jul 10, 2025 | A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function from... |
| CVE-2025-53637 | HIGH | 8 | 0.3% | Jul 10, 2025 | Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_reques... |
| CVE-2025-7415 | HIGH | 8.8 | 3.7% | Jul 10, 2025 | A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the f... |
| CVE-2025-7414 | HIGH | 8.8 | 12.7% | Jul 10, 2025 | A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function f... |
| CVE-2025-3947 | HIGH | 8.2 | 0.3% | Jul 10, 2025 | The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). A... |
| CVE-2025-3946 | HIGH | 8.2 | 0.5% | Jul 10, 2025 | The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the comp... |
| CVE-2025-2521 | HIGH | 8.6 | 0.4% | Jul 10, 2025 | The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Acce... |
| CVE-2025-7413 | HIGH | 8.8 | 0.3% | Jul 10, 2025 | A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part ... |
| CVE-2025-7412 | HIGH | 8.8 | 0.3% | Jul 10, 2025 | A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is ... |
| CVE-2025-53634 | HIGH | 7.5 | 0.4% | Jul 10, 2025 | Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes h... |
| CVE-2025-53630 | HIGH | 8.9 | 0.3% | Jul 10, 2025 | llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in g... |
| CVE-2025-53629 | HIGH | 7.5 | 0.5% | Jul 10, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests usi... |
| CVE-2025-53628 | HIGH | 8.8 | 0.4% | Jul 10, 2025 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not ... |
| CVE-2025-53506 | HIGH | 7.5 | 1.9% | Jul 10, 2025 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial set... |
| CVE-2025-34098 | HIGH | 7.1 | 0.7% | Jul 10, 2025 | A path traversal vulnerability exists in Riverbed SteelHead VCX appliances (confirmed in VCX255U 9.6.0a) due to improper... |
| CVE-2025-34097 | HIGH | 8.6 | 1.0% | Jul 10, 2025 | An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of upl... |
| CVE-2025-34093 | HIGH | 7.5 | 2.0% | Jul 10, 2025 | An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible ove... |
| CVE-2025-2520 | HIGH | 7.5 | 0.4% | Jul 10, 2025 | The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications.... |
| CVE-2025-53625 | HIGH | 8.7 | 0.4% | Jul 10, 2025 | The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with variou... |
| CVE-2025-53542 | HIGH | 7.7 | 0.7% | Jul 10, 2025 | Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now