2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43020 | MEDIUM | 6.8 | 0.2% | Jul 22, 2025 | A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.... |
| CVE-2025-8033 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr... |
| CVE-2025-8027 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, howeve... |
| CVE-2025-51462 | MEDIUM | 6.1 | 0.3% | Jul 22, 2025 | Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attack... |
| CVE-2025-51475 | MEDIUM | 5 | 0.8% | Jul 22, 2025 | Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows rem... |
| CVE-2025-51472 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execu... |
| CVE-2025-51458 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary S... |
| CVE-2025-31513 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the Is... |
| CVE-2025-51479 | MEDIUM | 5.4 | 0.3% | Jul 22, 2025 | Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated att... |
| CVE-2025-51471 | MEDIUM | 6.9 | 3.8% | Jul 22, 2025 | Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authen... |
| CVE-2025-51459 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers t... |
| CVE-2025-48964 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data co... |
| CVE-2025-51481 | MEDIUM | 6.6 | 0.5% | Jul 22, 2025 | Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC... |
| CVE-2025-7371 | MEDIUM | 6.8 | 0.3% | Jul 22, 2025 | Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vu... |
| CVE-2025-8015 | MEDIUM | 6.4 | 0.2% | Jul 22, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an ... |
| CVE-2025-51864 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, all... |
| CVE-2025-51863 | MEDIUM | 6.1 | 0.3% | Jul 22, 2025 | Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to exec... |
| CVE-2025-51862 | MEDIUM | 6.1 | 0.2% | Jul 22, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in TelegAI (telegai.com) thru 2025-05-26 in its chat component. An... |
| CVE-2025-51860 | MEDIUM | 6.1 | 0.3% | Jul 22, 2025 | Stored Cross-Site Scripting (XSS) in TelegAI (telegai.com) 2025-05-26 in its chat component and character container comp... |
| CVE-2025-51859 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Chaindesk thru 2025-05-26 in its agent chat component. An attacker ca... |
| CVE-2025-51858 | MEDIUM | 6.1 | 0.3% | Jul 22, 2025 | Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbit... |
| CVE-2025-51867 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing att... |
| CVE-2025-4295 | MEDIUM | 4.6 | 0.1% | Jul 22, 2025 | Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting. ... |
| CVE-2025-4294 | MEDIUM | 4.8 | 0.2% | Jul 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HotelRunner... |
| CVE-2025-34142 | MEDIUM | 6.9 | 0.9% | Jul 22, 2025 | An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/res... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now