2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53012 | HIGH | 7.5 | 0.8% | Aug 1, 2025 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren... |
| CVE-2025-53011 | HIGH | 7.5 | 0.5% | Aug 1, 2025 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren... |
| CVE-2025-53010 | HIGH | 7.5 | 0.4% | Aug 1, 2025 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren... |
| CVE-2025-53009 | HIGH | 7.5 | 0.6% | Aug 1, 2025 | MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren... |
| CVE-2025-50870 | CRITICAL | 9.8 | 0.3% | Aug 1, 2025 | Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The my... |
| CVE-2025-50869 | MEDIUM | 6.1 | 0.2% | Aug 1, 2025 | A stored Cross-Site Scripting (XSS) vulnerability exists in the qureydetails.php page of Institute-of-Current-Students 1... |
| CVE-2025-50868 | MEDIUM | 6.5 | 0.2% | Aug 1, 2025 | A SQL Injection vulnerability exists in the takeassessment2.php file of CloudClassroom-PHP-Project 1.0. The Q4 POST para... |
| CVE-2025-49832 | MEDIUM | 6.5 | 0.4% | Aug 1, 2025 | Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, betwe... |
| CVE-2025-33118 | MEDIUM | 5.4 | 0.2% | Aug 1, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows... |
| CVE-2025-2824 | HIGH | 7.4 | 0.3% | Aug 1, 2025 | IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to condu... |
| CVE-2025-51504 | HIGH | 7.6 | 0.5% | Aug 1, 2025 | Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last n... |
| CVE-2025-51502 | MEDIUM | 6.1 | 0.7% | Aug 1, 2025 | Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allow... |
| CVE-2025-51501 | MEDIUM | 6.1 | 0.7% | Aug 1, 2025 | Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS... |
| CVE-2025-48074 | MEDIUM | 5.5 | 0.2% | Aug 1, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-45778 | MEDIUM | 6.1 | 0.3% | Aug 1, 2025 | A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute... |
| CVE-2025-45150 | CRITICAL | 9.8 | 0.6% | Aug 1, 2025 | Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive... |
| CVE-2025-52390 | CRITICAL | 9.1 | 0.5% | Aug 1, 2025 | Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `p... |
| CVE-2025-52361 | HIGH | 7.8 | 0.2% | Aug 1, 2025 | Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allo... |
| CVE-2025-52327 | HIGH | 7.8 | 0.2% | Aug 1, 2025 | SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via t... |
| CVE-2025-50472 | CRITICAL | 9.8 | 1.2% | Aug 1, 2025 | The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untruste... |
| CVE-2025-50460 | CRITICAL | 9.8 | 2.3% | Aug 1, 2025 | A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization i... |
| CVE-2025-44139 | HIGH | 7.2 | 0.7% | Aug 1, 2025 | Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upl... |
| CVE-2025-45767 | HIGH | 7 | 0.1% | Aug 1, 2025 | jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do... |
| CVE-2025-46018 | MEDIUM | 5.4 | 0.3% | Aug 1, 2025 | CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorizat... |
| CVE-2025-41376 | MEDIUM | 5.3 | 0.5% | Aug 1, 2025 | CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now