2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53536 | HIGH | 8.1 | 0.7% | Jul 7, 2025 | Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker... |
| CVE-2025-20320 | HIGH | 7.3 | 0.4% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10... |
| CVE-2025-7137 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This a... |
| CVE-2025-53531 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT... |
| CVE-2025-53530 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT... |
| CVE-2025-1351 | HIGH | 7 | 0.1% | Jul 7, 2025 | IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another use... |
| CVE-2025-53376 | HIGH | 8.8 | 1.1% | Jul 7, 2025 | Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an... |
| CVE-2025-53373 | HIGH | 8.9 | 0.3% | Jul 7, 2025 | Natours is a Tour Booking API. The attacker can easily take over any victim account by injecting an attacker-controlled ... |
| CVE-2025-52492 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz,... |
| CVE-2025-48367 | HIGH | 7.5 | 0.7% | Jul 7, 2025 | Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP p... |
| CVE-2025-32023 | HIGH | 7.8 | 3.9% | Jul 7, 2025 | Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, ... |
| CVE-2025-26780 | HIGH | 7.5 | 0.3% | Jul 7, 2025 | An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length che... |
| CVE-2025-6807 | HIGH | 7.5 | 1.1% | Jul 7, 2025 | Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability a... |
| CVE-2025-6806 | HIGH | 7.5 | 1.2% | Jul 7, 2025 | Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows r... |
| CVE-2025-6804 | HIGH | 7.5 | 1.3% | Jul 7, 2025 | Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulner... |
| CVE-2025-6803 | HIGH | 7.5 | 1.3% | Jul 7, 2025 | Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerabilit... |
| CVE-2025-6801 | HIGH | 7.5 | 1.2% | Jul 7, 2025 | Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability ... |
| CVE-2025-6800 | HIGH | 7.5 | 1.3% | Jul 7, 2025 | Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerabili... |
| CVE-2025-6799 | HIGH | 7.5 | 1.3% | Jul 7, 2025 | Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability... |
| CVE-2025-6797 | HIGH | 7.5 | 1.3% | Jul 7, 2025 | Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability... |
| CVE-2025-6796 | HIGH | 7.5 | 1.3% | Jul 7, 2025 | Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability al... |
| CVE-2025-6795 | HIGH | 7.5 | 1.1% | Jul 7, 2025 | Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability ... |
| CVE-2025-6714 | HIGH | 7.5 | 0.3% | Jul 7, 2025 | MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete dat... |
| CVE-2025-6663 | HIGH | 7.8 | 0.3% | Jul 7, 2025 | GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2025-5987 | HIGH | 8.1 | 1.4% | Jul 7, 2025 | A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now