2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30480 | MEDIUM | 6.5 | 0.3% | Jul 30, 2025 | Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerP... |
| CVE-2025-30105 | MEDIUM | 5.5 | 0.1% | Jul 30, 2025 | Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low p... |
| CVE-2025-26332 | MEDIUM | 5.5 | 0.1% | Jul 30, 2025 | TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log ... |
| CVE-2025-45620 | HIGH | 8.1 | 0.8% | Jul 30, 2025 | An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request |
| CVE-2025-45619 | MEDIUM | 6.5 | 0.7% | Jul 30, 2025 | An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction ... |
| CVE-2025-36611 | HIGH | 7.8 | 0.1% | Jul 30, 2025 | Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Befo... |
| CVE-2025-25692 | MEDIUM | 6.5 | 0.8% | Jul 30, 2025 | A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitr... |
| CVE-2025-25691 | MEDIUM | 6.5 | 0.8% | Jul 30, 2025 | A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute ar... |
| CVE-2025-8353 | MEDIUM | 5.9 | 0.4% | Jul 30, 2025 | UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 an... |
| CVE-2025-8312 | HIGH | 7.1 | 0.3% | Jul 30, 2025 | Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its... |
| CVE-2025-54656 | MEDIUM | 6.5 | 0.5% | Jul 30, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affe... |
| CVE-2025-50578 | CRITICAL | 9.8 | 2.6% | Jul 30, 2025 | LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically ... |
| CVE-2025-54573 | MEDIUM | 6.5 | 0.3% | Jul 30, 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0... |
| CVE-2025-54433 | HIGH | 7.2 | 0.5% | Jul 30, 2025 | Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, ... |
| CVE-2025-53944 | HIGH | 7.7 | 0.4% | Jul 30, 2025 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6... |
| CVE-2025-53357 | MEDIUM | 5.4 | 0.2% | Jul 30, 2025 | GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that... |
| CVE-2025-53113 | LOW | 2.7 | 0.2% | Jul 30, 2025 | GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that... |
| CVE-2025-53112 | MEDIUM | 4.3 | 0.2% | Jul 30, 2025 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2025-53111 | MEDIUM | 6.5 | 0.2% | Jul 30, 2025 | GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks c... |
| CVE-2025-46811 | CRITICAL | 9.8 | 10.3% | Jul 30, 2025 | A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUS... |
| CVE-2025-43018 | MEDIUM | 5.3 | 0.3% | Jul 30, 2025 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a dev... |
| CVE-2025-54572 | MEDIUM | 6.9 | 0.4% | Jul 30, 2025 | The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denia... |
| CVE-2025-54430 | CRITICAL | 9.1 | 0.3% | Jul 30, 2025 | dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution qui... |
| CVE-2025-54425 | MEDIUM | 5.3 | 0.3% | Jul 30, 2025 | Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the conte... |
| CVE-2025-54410 | MEDIUM | 5.2 | 0.1% | Jul 30, 2025 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Conta... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now