2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7462 | MEDIUM | 5.3 | 0.4% | Jul 12, 2025 | A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as ... |
| CVE-2025-53636 | MEDIUM | 5.4 | 0.3% | Jul 11, 2025 | Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many e... |
| CVE-2025-7452 | MEDIUM | 6.3 | 0.3% | Jul 11, 2025 | A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as cr... |
| CVE-2025-53642 | MEDIUM | 6.5 | 0.2% | Jul 11, 2025 | haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a us... |
| CVE-2025-7450 | MEDIUM | 5.4 | 0.4% | Jul 11, 2025 | A vulnerability was found in letseeqiji gorobbs up to 1.0.8. It has been classified as critical. This affects the functi... |
| CVE-2025-47964 | MEDIUM | 4.3 | 0.4% | Jul 11, 2025 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2025-47963 | MEDIUM | 6.5 | 0.5% | Jul 11, 2025 | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a netw... |
| CVE-2025-47182 | MEDIUM | 5.6 | 0.3% | Jul 11, 2025 | Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature ... |
| CVE-2025-45582 | MEDIUM | 4.1 | 0.4% | Jul 11, 2025 | GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step proc... |
| CVE-2025-6549 | MEDIUM | 6.9 | 0.2% | Jul 11, 2025 | An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthen... |
| CVE-2025-52989 | MEDIUM | 6.8 | 0.1% | Jul 11, 2025 | An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allow... |
| CVE-2025-52986 | MEDIUM | 6.8 | 0.1% | Jul 11, 2025 | A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Netwo... |
| CVE-2025-52985 | MEDIUM | 6.9 | 0.2% | Jul 11, 2025 | A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an... |
| CVE-2025-52994 | MEDIUM | 4.9 | 0.7% | Jul 11, 2025 | gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. ... |
| CVE-2025-52963 | MEDIUM | 6.8 | 0.1% | Jul 11, 2025 | An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-pri... |
| CVE-2025-52958 | MEDIUM | 6 | 0.2% | Jul 11, 2025 | A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolv... |
| CVE-2025-52951 | MEDIUM | 6.9 | 0.3% | Jul 11, 2025 | A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker... |
| CVE-2025-48924 | MEDIUM | 5.3 | 2.2% | Jul 11, 2025 | Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with comm... |
| CVE-2025-6788 | MEDIUM | 5.3 | 0.3% | Jul 11, 2025 | A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong co... |
| CVE-2025-50125 | MEDIUM | 6.3 | 0.5% | Jul 11, 2025 | A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execu... |
| CVE-2025-3933 | MEDIUM | 5.3 | 0.4% | Jul 11, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp... |
| CVE-2025-6851 | MEDIUM | 6.5 | 0.6% | Jul 11, 2025 | The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in... |
| CVE-2025-6838 | MEDIUM | 4.1 | 0.2% | Jul 11, 2025 | The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0... |
| CVE-2025-6438 | MEDIUM | 5.9 | 0.4% | Jul 11, 2025 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulati... |
| CVE-2025-6745 | MEDIUM | 5.3 | 0.3% | Jul 11, 2025 | The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now