2025 CVE Vulnerabilities
45,173 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23269 | MEDIUM | 4.7 | 0.1% | Jul 17, 2025 | NVIDIA Jetson Linux contains a vulnerability in the kernel where an attacker may cause an exposure of sensitive informat... |
| CVE-2025-6230 | MEDIUM | 5.3 | 0.2% | Jul 17, 2025 | A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLit... |
| CVE-2025-2818 | MEDIUM | 5.1 | 0.1% | Jul 17, 2025 | A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Co... |
| CVE-2025-1729 | MEDIUM | 6.7 | 0.1% | Jul 17, 2025 | A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow... |
| CVE-2025-54070 | MEDIUM | 6.9 | 0.3% | Jul 17, 2025 | OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 5.2.0 and prior to versio... |
| CVE-2025-46102 | MEDIUM | 5.4 | 0.3% | Jul 17, 2025 | Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Referenc... |
| CVE-2025-53638 | MEDIUM | 6.9 | 0.3% | Jul 17, 2025 | Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, w... |
| CVE-2025-51497 | MEDIUM | 5.5 | 0.1% | Jul 17, 2025 | An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Saf... |
| CVE-2025-54066 | MEDIUM | 4.7 | 0.3% | Jul 17, 2025 | DiracX-Web is a web application that provides an interface to interact with the DiracX services. Prior to version 0.1.0-... |
| CVE-2025-54064 | MEDIUM | 6.9 | 0.4% | Jul 17, 2025 | Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da... |
| CVE-2025-47189 | MEDIUM | 6.1 | 0.2% | Jul 17, 2025 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d... |
| CVE-2025-53941 | MEDIUM | 6.1 | 0.2% | Jul 17, 2025 | Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to ... |
| CVE-2025-53927 | MEDIUM | 6.3 | 0.2% | Jul 17, 2025 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed be... |
| CVE-2025-40924 | MEDIUM | 6.5 | 0.3% | Jul 17, 2025 | Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated fr... |
| CVE-2025-5346 | MEDIUM | 5.1 | 0.1% | Jul 17, 2025 | Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast recei... |
| CVE-2025-5345 | MEDIUM | 6.3 | 0.1% | Jul 17, 2025 | Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "... |
| CVE-2025-3415 | MEDIUM | 4.3 | 0.9% | Jul 17, 2025 | Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p... |
| CVE-2025-4302 | MEDIUM | 5.3 | 0.8% | Jul 17, 2025 | The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-a... |
| CVE-2025-7729 | MEDIUM | 5.4 | 0.3% | Jul 17, 2025 | A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unk... |
| CVE-2025-7728 | MEDIUM | 5.4 | 0.3% | Jul 17, 2025 | A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of ... |
| CVE-2025-6983 | MEDIUM | 5.1 | 0.4% | Jul 16, 2025 | A Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into perfor... |
| CVE-2025-6982 | MEDIUM | 6.9 | 0.3% | Jul 16, 2025 | Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 ... |
| CVE-2025-20288 | MEDIUM | 5.3 | 0.3% | Jul 16, 2025 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate... |
| CVE-2025-20285 | MEDIUM | 4.1 | 0.3% | Jul 16, 2025 | A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote... |
| CVE-2025-20272 | MEDIUM | 4.3 | 0.3% | Jul 16, 2025 | A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (E... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now