2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22220 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative... |
| CVE-2025-23367 | MEDIUM | 6.5 | 0.7% | Jan 30, 2025 | A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control manageme... |
| CVE-2025-0871 | MEDIUM | 5.3 | 0.3% | Jan 30, 2025 | A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/a... |
| CVE-2025-0870 | MEDIUM | 5.9 | 0.5% | Jan 30, 2025 | A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is ... |
| CVE-2025-0869 | MEDIUM | 5.3 | 0.4% | Jan 30, 2025 | A vulnerability was found in Cianet ONU GW24AC up to 20250127. It has been declared as problematic. Affected by this vul... |
| CVE-2025-0747 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attack... |
| CVE-2025-0746 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an aut... |
| CVE-2025-0745 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic... |
| CVE-2025-0744 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic... |
| CVE-2025-0743 | MEDIUM | 4.3 | 0.3% | Jan 30, 2025 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic... |
| CVE-2025-0742 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic... |
| CVE-2025-0741 | MEDIUM | 4.3 | 0.2% | Jan 30, 2025 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authent... |
| CVE-2025-0740 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authent... |
| CVE-2025-0739 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic... |
| CVE-2025-23007 | MEDIUM | 5.5 | 0.2% | Jan 30, 2025 | A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows sy... |
| CVE-2025-0860 | MEDIUM | 6.1 | 0.3% | Jan 30, 2025 | The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several ... |
| CVE-2025-23374 | MEDIUM | 4.9 | 0.3% | Jan 30, 2025 | Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Se... |
| CVE-2025-0662 | MEDIUM | 4.9 | 0.3% | Jan 30, 2025 | In some cases, the ktrace facility will log the contents of kernel structures to userspace. In one such case, ktrace du... |
| CVE-2025-0374 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcup... |
| CVE-2025-0373 | MEDIUM | 6 | 0.4% | Jan 30, 2025 | On 64-bit systems, the implementation of VOP_VPTOFH() in the cd9660, tarfs and ext2fs filesystems overflows the destinat... |
| CVE-2025-0844 | MEDIUM | 6.1 | 0.5% | Jan 30, 2025 | A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vu... |
| CVE-2025-24884 | MEDIUM | 5.1 | 0.2% | Jan 29, 2025 | kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vec... |
| CVE-2025-24795 | MEDIUM | 5.5 | 0.1% | Jan 29, 2025 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak... |
| CVE-2025-24788 | MEDIUM | 5.5 | 0.1% | Jan 29, 2025 | snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the ... |
| CVE-2025-24882 | MEDIUM | 5.2 | 0.2% | Jan 29, 2025 | regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned m... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now