2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54136 | HIGH | 8.8 | 7.5% | Aug 2, 2025 | Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per... |
| CVE-2025-54133 | CRITICAL | 9.6 | 0.3% | Aug 2, 2025 | Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosur... |
| CVE-2025-54792 | MEDIUM | 6.8 | 0.2% | Aug 1, 2025 | LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without nee... |
| CVE-2025-54424 | CRITICAL | 9.8 | 0.9% | Aug 1, 2025 | 1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server... |
| CVE-2025-54132 | HIGH | 7.5 | 0.3% | Aug 1, 2025 | Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams)... |
| CVE-2025-54131 | HIGH | 8.8 | 0.5% | Aug 1, 2025 | Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in a... |
| CVE-2025-8480 | HIGH | 8 | 0.7% | Aug 1, 2025 | Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute ... |
| CVE-2025-8477 | HIGH | 7.4 | 0.3% | Aug 1, 2025 | Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2025-8476 | HIGH | 8 | 0.1% | Aug 1, 2025 | Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers... |
| CVE-2025-8475 | HIGH | 7.4 | 0.3% | Aug 1, 2025 | Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-... |
| CVE-2025-8474 | MEDIUM | 6.8 | 0.3% | Aug 1, 2025 | Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically pr... |
| CVE-2025-8473 | MEDIUM | 6.6 | 0.7% | Aug 1, 2025 | Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attack... |
| CVE-2025-8472 | HIGH | 7.4 | 0.3% | Aug 1, 2025 | Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2025-6037 | MEDIUM | 6.8 | 0.2% | Aug 1, 2025 | Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when con... |
| CVE-2025-6015 | MEDIUM | 5.7 | 0.3% | Aug 1, 2025 | Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in... |
| CVE-2025-6014 | MEDIUM | 6.5 | 0.3% | Aug 1, 2025 | Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within ... |
| CVE-2025-6011 | LOW | 3.7 | 0.3% | Aug 1, 2025 | A timing side channel in Vault and Vault Enterprise’s (“Vault”) userpass auth method allowed an attacker to distinguish ... |
| CVE-2025-6004 | MEDIUM | 5.3 | 0.4% | Aug 1, 2025 | Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication metho... |
| CVE-2025-6000 | CRITICAL | 9.1 | 0.9% | Aug 1, 2025 | A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution o... |
| CVE-2025-5999 | HIGH | 7.2 | 0.5% | Aug 1, 2025 | A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or... |
| CVE-2025-54595 | HIGH | 7.3 | 0.2% | Aug 1, 2025 | Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged he... |
| CVE-2025-54593 | HIGH | 7.2 | 0.7% | Aug 1, 2025 | FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can ... |
| CVE-2025-54590 | MEDIUM | 6.9 | 0.6% | Aug 1, 2025 | webfinger.js is a TypeScript-based WebFinger client that runs in both browsers and Node.js environments. In versions 2.8... |
| CVE-2025-54574 | CRITICAL | 9.8 | 23.5% | Aug 1, 2025 | Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possi... |
| CVE-2025-54564 | HIGH | 7.8 | 0.2% | Aug 1, 2025 | uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now