2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7675 | HIGH | 7.8 | 0.2% | Jul 29, 2025 | A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab... |
| CVE-2025-7497 | HIGH | 7.8 | 0.2% | Jul 29, 2025 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab... |
| CVE-2025-6637 | HIGH | 7.8 | 0.2% | Jul 29, 2025 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab... |
| CVE-2025-6636 | HIGH | 7.8 | 0.2% | Jul 29, 2025 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability.... |
| CVE-2025-6635 | HIGH | 7.8 | 0.2% | Jul 29, 2025 | A maliciously crafted PRT file, when linked or imported into certain Autodesk products, can force an Out-of-Bounds Read ... |
| CVE-2025-6631 | HIGH | 7.8 | 0.2% | Jul 29, 2025 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab... |
| CVE-2025-5043 | HIGH | 7.8 | 0.2% | Jul 29, 2025 | A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow ... |
| CVE-2025-5038 | HIGH | 7.8 | 0.2% | Jul 29, 2025 | A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili... |
| CVE-2025-53715 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/Wan6to4TunnelCfgRpm.ht... |
| CVE-2025-53714 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WzdWlanSiteSurveyRpm_A... |
| CVE-2025-53713 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_APC.htm... |
| CVE-2025-53712 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm/WlanNetworkRpm_AP.htm ... |
| CVE-2025-53711 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | A vulnerability has been found in TP-Link TL-WR841N v11, TL-WR842ND v2 and TL-WR494N v3. The vulnerability exists in the... |
| CVE-2025-52284 | MEDIUM | 6.5 | 2.2% | Jul 29, 2025 | Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 functio... |
| CVE-2025-36010 | HIGH | 7.5 | 0.2% | Jul 29, 2025 | IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial of service due to e... |
| CVE-2025-2928 | HIGH | 7.2 | 0.3% | Jul 29, 2025 | SQL Injection affecting the Archiver role. |
| CVE-2025-2533 | HIGH | 7.5 | 0.3% | Jul 29, 2025 | IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain ... |
| CVE-2025-2179 | MEDIUM | 6.8 | 0.1% | Jul 29, 2025 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a ... |
| CVE-2025-27514 | MEDIUM | 5.4 | 0.2% | Jul 29, 2025 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2025-5922 | MEDIUM | 4.8 | 0.1% | Jul 29, 2025 | Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and r... |
| CVE-2025-54432 | — | — | — | Jul 29, 2025 | Rejected reason: This CVE is a duplicate of another CVE. See CVE-2018-25031 and CVE-2021-46708. |
| CVE-2025-54420 | — | — | — | Jul 29, 2025 | Rejected reason: This CVE is a duplicate of CVE-2025-8129. |
| CVE-2025-44137 | HIGH | 8.2 | 1.3% | Jul 29, 2025 | MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is resp... |
| CVE-2025-44136 | CRITICAL | 9.8 | 2.4% | Jul 29, 2025 | MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e... |
| CVE-2025-31965 | HIGH | 8.2 | 0.2% | Jul 29, 2025 | Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now