2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49537 | HIGH | 7.9 | 2.6% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements ... |
| CVE-2025-49536 | HIGH | 7.3 | 0.3% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that c... |
| CVE-2025-43582 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Substance3D - Viewer versions 0.22 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could res... |
| CVE-2025-7192 | HIGH | 8.8 | 4.0% | Jul 8, 2025 | A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ss... |
| CVE-2025-53355 | HIGH | 7.5 | 2.2% | Jul 8, 2025 | MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulne... |
| CVE-2025-7190 | HIGH | 8.8 | 0.3% | Jul 8, 2025 | A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affect... |
| CVE-2025-48385 | HIGH | 8.6 | 0.8% | Jul 8, 2025 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-... |
| CVE-2025-48384 | HIGH | 8 | 2.8% | Jul 8, 2025 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-... |
| CVE-2025-37102 | HIGH | 7.2 | 1.5% | Jul 8, 2025 | An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Acces... |
| CVE-2025-7189 | HIGH | 8.8 | 0.4% | Jul 8, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this iss... |
| CVE-2025-7188 | HIGH | 8.8 | 0.4% | Jul 8, 2025 | A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an ... |
| CVE-2025-30312 | HIGH | 7.8 | 0.2% | Jul 8, 2025 | Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary... |
| CVE-2025-0928 | HIGH | 8.8 | 0.6% | Jul 8, 2025 | In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent bina... |
| CVE-2025-7187 | HIGH | 8.8 | 0.4% | Jul 8, 2025 | A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function ... |
| CVE-2025-7186 | HIGH | 8.8 | 0.4% | Jul 8, 2025 | A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unkno... |
| CVE-2025-49753 | HIGH | 8.8 | 0.7% | Jul 8, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-49744 | HIGH | 7 | 0.7% | Jul 8, 2025 | Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49742 | HIGH | 7.8 | 0.3% | Jul 8, 2025 | Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally. |
| CVE-2025-49740 | HIGH | 8.8 | 0.7% | Jul 8, 2025 | Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a ... |
| CVE-2025-49739 | HIGH | 8.8 | 0.8% | Jul 8, 2025 | Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to eleva... |
| CVE-2025-49738 | HIGH | 7.8 | 0.3% | Jul 8, 2025 | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to ... |
| CVE-2025-49737 | HIGH | 7 | 0.2% | Jul 8, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an... |
| CVE-2025-49735 | HIGH | 8.1 | 1.1% | Jul 8, 2025 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49733 | HIGH | 7.8 | 0.3% | Jul 8, 2025 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49732 | HIGH | 7.8 | 0.3% | Jul 8, 2025 | Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now