2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54789 | MEDIUM | 6.1 | 0.3% | Aug 2, 2025 | Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functi... |
| CVE-2025-54792 | MEDIUM | 6.8 | 0.2% | Aug 1, 2025 | LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without nee... |
| CVE-2025-8474 | MEDIUM | 6.8 | 0.3% | Aug 1, 2025 | Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically pr... |
| CVE-2025-8473 | MEDIUM | 6.6 | 0.7% | Aug 1, 2025 | Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attack... |
| CVE-2025-6037 | MEDIUM | 6.8 | 0.2% | Aug 1, 2025 | Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when con... |
| CVE-2025-6015 | MEDIUM | 5.7 | 0.3% | Aug 1, 2025 | Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in... |
| CVE-2025-6014 | MEDIUM | 6.5 | 0.3% | Aug 1, 2025 | Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within ... |
| CVE-2025-6004 | MEDIUM | 5.3 | 0.4% | Aug 1, 2025 | Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication metho... |
| CVE-2025-54590 | MEDIUM | 6.9 | 0.6% | Aug 1, 2025 | webfinger.js is a TypeScript-based WebFinger client that runs in both browsers and Node.js environments. In versions 2.8... |
| CVE-2025-50869 | MEDIUM | 6.1 | 0.2% | Aug 1, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in the qureydetails.php page of Institute-of-Current-Students 1... |
| CVE-2025-50868 | MEDIUM | 6.5 | 0.2% | Aug 1, 2025 | A SQL Injection vulnerability exists in the takeassessment2.php file of CloudClassroom-PHP-Project 1.0. The Q4 POST para... |
| CVE-2025-49832 | MEDIUM | 6.5 | 0.4% | Aug 1, 2025 | Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, betwe... |
| CVE-2025-33118 | MEDIUM | 5.4 | 0.2% | Aug 1, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows... |
| CVE-2025-51502 | MEDIUM | 6.1 | 0.7% | Aug 1, 2025 | Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allow... |
| CVE-2025-51501 | MEDIUM | 6.1 | 0.7% | Aug 1, 2025 | Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS... |
| CVE-2025-48074 | MEDIUM | 5.5 | 0.2% | Aug 1, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-45778 | MEDIUM | 6.1 | 0.3% | Aug 1, 2025 | A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute... |
| CVE-2025-46018 | MEDIUM | 5.4 | 0.3% | Aug 1, 2025 | CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorizat... |
| CVE-2025-41376 | MEDIUM | 5.3 | 0.5% | Aug 1, 2025 | CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject a... |
| CVE-2025-6228 | MEDIUM | 6.4 | 0.3% | Aug 1, 2025 | The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Tabl... |
| CVE-2025-4684 | MEDIUM | 6.4 | 0.2% | Aug 1, 2025 | The BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Count... |
| CVE-2025-6398 | MEDIUM | 6.7 | 0.1% | Aug 1, 2025 | A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be t... |
| CVE-2025-7646 | MEDIUM | 6.4 | 0.2% | Aug 1, 2025 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2025-5921 | MEDIUM | 5.8 | 0.2% | Aug 1, 2025 | The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2025-31716 | MEDIUM | 5.1 | 0.1% | Aug 1, 2025 | In bootloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now