2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52434 | HIGH | 7.5 | 1.8% | Jul 10, 2025 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc... |
| CVE-2025-28244 | HIGH | 8.8 | 0.5% | Jul 10, 2025 | Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain... |
| CVE-2025-28243 | HIGH | 8 | 0.3% | Jul 10, 2025 | An issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component. |
| CVE-2025-53020 | HIGH | 7.5 | 4.4% | Jul 10, 2025 | Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Ser... |
| CVE-2025-49812 | HIGH | 7.4 | 0.5% | Jul 10, 2025 | In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows... |
| CVE-2025-49630 | HIGH | 7.5 | 1.1% | Jul 10, 2025 | In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63... |
| CVE-2025-27889 | HIGH | 8.8 | 0.4% | Jul 10, 2025 | Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint... |
| CVE-2025-7365 | HIGH | 7.1 | 0.2% | Jul 10, 2025 | A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account du... |
| CVE-2025-46835 | HIGH | 8.5 | 0.3% | Jul 10, 2025 | Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository ... |
| CVE-2025-46334 | HIGH | 8.6 | 0.3% | Jul 10, 2025 | Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of... |
| CVE-2025-44251 | HIGH | 7.5 | 0.2% | Jul 10, 2025 | Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process. |
| CVE-2025-27614 | HIGH | 8.6 | 0.3% | Jul 10, 2025 | Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that wit... |
| CVE-2025-7425 | HIGH | 7.8 | 0.3% | Jul 10, 2025 | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory m... |
| CVE-2025-7424 | HIGH | 7.5 | 1.2% | Jul 10, 2025 | A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which ... |
| CVE-2025-7407 | HIGH | 8.8 | 8.3% | Jul 10, 2025 | A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of... |
| CVE-2025-5040 | HIGH | 7.8 | 0.2% | Jul 10, 2025 | A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A mal... |
| CVE-2025-5037 | HIGH | 7.8 | 0.4% | Jul 10, 2025 | A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerabi... |
| CVE-2025-32990 | HIGH | 8.2 | 0.7% | Jul 10, 2025 | A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certt... |
| CVE-2025-6948 | HIGH | 8 | 0.5% | Jul 10, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 1... |
| CVE-2025-5023 | HIGH | 7.1 | 0.2% | Jul 10, 2025 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB”... |
| CVE-2025-38348 | HIGH | 7.8 | 0.2% | Jul 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: p54: prevent buffer-overflow in p54_rx_eeprom... |
| CVE-2025-38346 | HIGH | 7.8 | 0.2% | Jul 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix UAF when lookup kallsym after ftrace di... |
| CVE-2025-38342 | HIGH | 7.1 | 0.2% | Jul 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node... |
| CVE-2025-38341 | HIGH | 7.8 | 0.2% | Jul 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: avoid double free when failing to DMA-m... |
| CVE-2025-38340 | HIGH | 7.1 | 0.1% | Jul 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix OOB memory read access in KUn... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now