2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6633 | HIGH | 7.8 | 0.2% | Aug 6, 2025 | A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ... |
| CVE-2025-6632 | HIGH | 7.8 | 0.2% | Aug 6, 2025 | A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerabi... |
| CVE-2025-51058 | MEDIUM | 6.5 | 0.5% | Aug 6, 2025 | Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/pr... |
| CVE-2025-51057 | MEDIUM | 6.5 | 0.5% | Aug 6, 2025 | A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read a... |
| CVE-2025-51056 | HIGH | 8.2 | 0.5% | Aug 6, 2025 | An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write t... |
| CVE-2025-51055 | HIGH | 8.6 | 0.3% | Aug 6, 2025 | Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 202... |
| CVE-2025-51054 | MEDIUM | 6.5 | 0.4% | Aug 6, 2025 | Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privi... |
| CVE-2025-51053 | MEDIUM | 6.1 | 0.4% | Aug 6, 2025 | A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject... |
| CVE-2025-51052 | MEDIUM | 6.5 | 0.4% | Aug 6, 2025 | A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem ... |
| CVE-2025-50740 | MEDIUM | 6.1 | 0.2% | Aug 6, 2025 | AutoConnect 1.4.2, an Arduino library, is vulnerable to a cross site scripting (xss) vulnerability. The AutoConnect web ... |
| CVE-2025-47908 | HIGH | 7.5 | 0.5% | Aug 6, 2025 | Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a A... |
| CVE-2025-46660 | MEDIUM | 5.3 | 0.3% | Aug 6, 2025 | An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt. |
| CVE-2025-51624 | HIGH | 7.6 | 0.3% | Aug 6, 2025 | Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0. |
| CVE-2025-46659 | HIGH | 7.5 | 0.3% | Aug 6, 2025 | An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HT... |
| CVE-2025-45766 | HIGH | 7 | 0.1% | Aug 6, 2025 | poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key... |
| CVE-2025-45764 | LOW | 3.2 | 0.1% | Aug 6, 2025 | jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue has been disputed by a third party who bel... |
| CVE-2025-38747 | HIGH | 7.8 | 0.1% | Aug 6, 2025 | Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissio... |
| CVE-2025-38746 | LOW | 2.4 | 0.2% | Aug 6, 2025 | Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthor... |
| CVE-2025-8130 | — | — | — | Aug 6, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-8667 | MEDIUM | 6.3 | 2.2% | Aug 6, 2025 | A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75b... |
| CVE-2025-8665 | MEDIUM | 6.3 | 2.2% | Aug 6, 2025 | A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the f... |
| CVE-2025-8419 | MEDIUM | 5.3 | 0.4% | Aug 6, 2025 | A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Inje... |
| CVE-2025-30127 | CRITICAL | 9.8 | 0.4% | Aug 6, 2025 | An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or c... |
| CVE-2025-20332 | MEDIUM | 4.3 | 0.4% | Aug 6, 2025 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modi... |
| CVE-2025-20331 | MEDIUM | 5.4 | 0.2% | Aug 6, 2025 | A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now