2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52896 | MEDIUM | 5.4 | 0.2% | Jun 30, 2025 | Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could uploa... |
| CVE-2025-52895 | HIGH | 7.5 | 0.3% | Jun 30, 2025 | Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved... |
| CVE-2025-47871 | MEDIUM | 5.4 | 0.2% | Jun 30, 2025 | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr... |
| CVE-2025-46702 | MEDIUM | 5.4 | 0.2% | Jun 30, 2025 | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr... |
| CVE-2025-45931 | CRITICAL | 9.8 | 1.3% | Jun 30, 2025 | An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via sy... |
| CVE-2025-45143 | HIGH | 7 | 0.4% | Jun 30, 2025 | string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input. |
| CVE-2025-26074 | CRITICAL | 9.8 | 0.6% | Jun 30, 2025 | Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java cl... |
| CVE-2025-6914 | HIGH | 8.8 | 0.3% | Jun 30, 2025 | A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability... |
| CVE-2025-6913 | HIGH | 8.8 | 0.3% | Jun 30, 2025 | A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown fu... |
| CVE-2025-53017 | — | — | — | Jun 30, 2025 | Rejected reason: Reason: This candidate was issued in error. |
| CVE-2025-53001 | — | — | — | Jun 30, 2025 | Rejected reason: Reason: This candidate was issued in error. |
| CVE-2025-6912 | HIGH | 8.8 | 0.3% | Jun 30, 2025 | A vulnerability was found in PHPGurukul Student Record System 3.2. It has been rated as critical. This issue affects som... |
| CVE-2025-6911 | HIGH | 8.8 | 0.3% | Jun 30, 2025 | A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability ... |
| CVE-2025-2895 | MEDIUM | 5.4 | 0.2% | Jun 30, 2025 | IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to... |
| CVE-2025-6910 | HIGH | 8.8 | 0.3% | Jun 30, 2025 | A vulnerability was found in PHPGurukul Student Record System 3.2. It has been classified as critical. This affects an u... |
| CVE-2025-6909 | HIGH | 8.8 | 0.3% | Jun 30, 2025 | A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by ... |
| CVE-2025-6908 | HIGH | 8.8 | 0.3% | Jun 30, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected ... |
| CVE-2025-6907 | CRITICAL | 9.8 | 0.4% | Jun 30, 2025 | A vulnerability classified as critical was found in code-projects Car Rental System 1.0. This vulnerability affects unkn... |
| CVE-2025-6906 | CRITICAL | 9.8 | 0.4% | Jun 30, 2025 | A vulnerability classified as critical has been found in code-projects Car Rental System 1.0. This affects an unknown pa... |
| CVE-2025-6905 | CRITICAL | 9.8 | 0.4% | Jun 30, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Car Rental System 1.0. This issue aff... |
| CVE-2025-4407 | MEDIUM | 6.8 | 0.2% | Jun 30, 2025 | Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1. |
| CVE-2025-6904 | CRITICAL | 9.8 | 0.4% | Jun 30, 2025 | A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. Affected by this issue ... |
| CVE-2025-6903 | CRITICAL | 9.8 | 0.4% | Jun 30, 2025 | A vulnerability was found in code-projects Car Rental System 1.0. It has been declared as critical. Affected by this vul... |
| CVE-2025-40710 | LOW | 2.3 | 0.3% | Jun 30, 2025 | Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when a... |
| CVE-2025-6902 | CRITICAL | 9.8 | 0.4% | Jun 30, 2025 | A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. Affected... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now