2025 CVE Vulnerabilities
45,180 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49539 | MEDIUM | 4.5 | 0.5% | Jul 8, 2025 | ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity ... |
| CVE-2025-43584 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to di... |
| CVE-2025-43583 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Substance3D - Viewer versions 0.22 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead ... |
| CVE-2025-48386 | MEDIUM | 6.3 | 0.3% | Jul 8, 2025 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-... |
| CVE-2025-27369 | MEDIUM | 4.3 | 0.2% | Jul 8, 2025 | IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a ... |
| CVE-2025-27367 | MEDIUM | 6.5 | 0.2% | Jul 8, 2025 | IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side v... |
| CVE-2025-7363 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User i... |
| CVE-2025-7362 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted ... |
| CVE-2025-53479 | MEDIUM | 5.4 | 0.2% | Jul 8, 2025 | The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. T... |
| CVE-2025-4663 | MEDIUM | 4.9 | 0.3% | Jul 8, 2025 | An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow ... |
| CVE-2025-47135 | MEDIUM | 5.5 | 0.2% | Jul 8, 2025 | Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure o... |
| CVE-2025-53513 | MEDIUM | 6.5 | 0.6% | Jul 8, 2025 | The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on t... |
| CVE-2025-53512 | MEDIUM | 6.5 | 0.3% | Jul 8, 2025 | The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access deb... |
| CVE-2025-49722 | MEDIUM | 5.7 | 0.5% | Jul 8, 2025 | Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over... |
| CVE-2025-49706 | MEDIUM | 6.5 | 99.9% | Jul 8, 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ... |
| CVE-2025-49684 | MEDIUM | 5.5 | 0.4% | Jul 8, 2025 | Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally. |
| CVE-2025-49681 | MEDIUM | 6.5 | 1.0% | Jul 8, 2025 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor... |
| CVE-2025-49671 | MEDIUM | 6.5 | 1.0% | Jul 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an... |
| CVE-2025-49670 | MEDIUM | 6.5 | 0.9% | Jul 8, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-49664 | MEDIUM | 5.5 | 0.5% | Jul 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authoriz... |
| CVE-2025-49658 | MEDIUM | 5.5 | 0.4% | Jul 8, 2025 | Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally. |
| CVE-2025-48823 | MEDIUM | 5.9 | 0.6% | Jul 8, 2025 | Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a ne... |
| CVE-2025-48818 | MEDIUM | 6.8 | 0.4% | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a secur... |
| CVE-2025-48812 | MEDIUM | 5.5 | 0.5% | Jul 8, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2025-48811 | MEDIUM | 6.7 | 0.3% | Jul 8, 2025 | Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now