2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54583 | MEDIUM | 6.5 | 0.4% | Jul 30, 2025 | GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 ... |
| CVE-2025-54575 | MEDIUM | 5.3 | 0.4% | Jul 30, 2025 | ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file con... |
| CVE-2025-51954 | MEDIUM | 6.1 | 0.3% | Jul 30, 2025 | playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2025-51951 | MEDIUM | 6.1 | 0.3% | Jul 30, 2025 | andisearch v0.5.249 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2025-50464 | MEDIUM | 6.5 | 0.5% | Jul 30, 2025 | A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability ar... |
| CVE-2025-36608 | MEDIUM | 6.5 | 0.5% | Jul 30, 2025 | Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Refe... |
| CVE-2025-30103 | MEDIUM | 5.5 | 0.2% | Jul 30, 2025 | Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Partie... |
| CVE-2025-30480 | MEDIUM | 6.5 | 0.3% | Jul 30, 2025 | Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerP... |
| CVE-2025-30105 | MEDIUM | 5.5 | 0.1% | Jul 30, 2025 | Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low p... |
| CVE-2025-26332 | MEDIUM | 5.5 | 0.1% | Jul 30, 2025 | TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log ... |
| CVE-2025-45619 | MEDIUM | 6.5 | 0.7% | Jul 30, 2025 | An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction ... |
| CVE-2025-25692 | MEDIUM | 6.5 | 0.8% | Jul 30, 2025 | A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitr... |
| CVE-2025-25691 | MEDIUM | 6.5 | 0.8% | Jul 30, 2025 | A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute ar... |
| CVE-2025-8353 | MEDIUM | 5.9 | 0.4% | Jul 30, 2025 | UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 an... |
| CVE-2025-54656 | MEDIUM | 6.5 | 0.5% | Jul 30, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affe... |
| CVE-2025-54573 | MEDIUM | 6.5 | 0.3% | Jul 30, 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0... |
| CVE-2025-53357 | MEDIUM | 5.4 | 0.2% | Jul 30, 2025 | GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that... |
| CVE-2025-53112 | MEDIUM | 4.3 | 0.2% | Jul 30, 2025 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2025-53111 | MEDIUM | 6.5 | 0.2% | Jul 30, 2025 | GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks c... |
| CVE-2025-43018 | MEDIUM | 5.3 | 0.3% | Jul 30, 2025 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a dev... |
| CVE-2025-54572 | MEDIUM | 6.9 | 0.4% | Jul 30, 2025 | The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denia... |
| CVE-2025-54425 | MEDIUM | 5.3 | 0.3% | Jul 30, 2025 | Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the conte... |
| CVE-2025-54410 | MEDIUM | 5.2 | 0.1% | Jul 30, 2025 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Conta... |
| CVE-2025-54388 | MEDIUM | 4.6 | 0.2% | Jul 30, 2025 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Conta... |
| CVE-2025-53008 | MEDIUM | 6.5 | 0.2% | Jul 30, 2025 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now